An internet of things device defense resource allocation method and device, and a terminal device
By acquiring information from IoT devices and optimizing the allocation of defense resources using the Stackelberg game model, the problem of insufficient security for IoT devices is solved, dynamic adaptation to topology and service requirements is achieved, and the protection capabilities of IoT devices are improved.
Patent Information
- Application Number
- CN202511231813.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-01
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-09-01
AI Technical Summary
Existing IoT devices have not adequately considered security during the design phase, resulting in numerous vulnerabilities. They are also unable to adapt to dynamic changes in topology and service requirements, and cannot effectively proactively defend against attack risks.
By acquiring the identification information, operating status information, topology information, and communication characterization information of IoT devices, the importance and interaction level of the devices are calculated, initial defense resource allocation information and attack probability are generated, and the Stackelberg game model is used to optimize the allocation of defense resources and respond to the attack and defense process between attackers and defenders in real time.
It improves the flexibility and timeliness of resource allocation for IoT device defense, enabling timely responses to external intrusions and lateral movement attacks, enhancing dynamic protection capabilities, and reducing losses after devices are attacked.
Smart Images

Figure CN120750657B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of Internet of Things (IoT) technology, and in particular relates to IoT device defense resource allocation methods, devices, and terminal equipment. Background Technology
[0002] With the rapid development of smart device technology, the Internet of Things (IoT) has become an indispensable part of our daily lives. IoT has demonstrated enormous application potential in multiple industries, including smart homes, smart education, intelligent transportation, healthcare, and health monitoring. Compared to traditional network systems, IoT exhibits significant advantages in the discovery, allocation, and sharing of network information and resources. However, with technological advancements and widespread application, IoT security issues have become increasingly prominent. Currently, many IoT devices are not adequately designed with security in mind, resulting in numerous vulnerabilities that make them easy targets for attackers, leading to privacy breaches and data security problems. Therefore, strengthening the security protection of IoT devices and improving their ability to resist attacks has become a critical task that urgently needs to be addressed. This requires comprehensive measures from hardware design and software development to network monitoring to ensure the overall security of the IoT system.
[0003] In existing technologies, some manufacturers enhance device security by integrating secure hardware encryption modules and providing remote update capabilities, and utilize protocols such as TLS / DTLS to ensure encrypted data transmission. However, these measures often exhibit a degree of lag, struggling to adapt to the dynamic changes in IoT topologies and service demands, resulting in ineffective proactive defense against attack risks. Therefore, while these technologies contribute to improving device security, their limitations weaken the overall security capabilities of IoT devices to some extent. To address this issue, there is an urgent need to develop security strategies that can respond and adjust in real time to better cope with dynamically changing network environments. Summary of the Invention
[0004] In view of this, embodiments of this application propose a method, apparatus, and terminal device for allocating defense resources for IoT devices, designed to adapt to the dynamic changes in IoT topology and service requirements. By optimizing defense resource management, this embodiment can protect critical devices in the network in real time, effectively mitigating losses to IoT systems caused by malicious threats.
[0005] The first aspect of this application provides a method for allocating defense resources for Internet of Things (IoT) devices, including:
[0006] Obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characteristics between IoT devices;
[0007] Based on the IoT device identification information, IoT topology information, IoT device operating status information, and communication characterization information between IoT devices, multiple device importance characterization information and multiple device interaction characterization information are calculated.
[0008] Generate multiple initial IoT device defense resource allocation information and multiple device attack probability information;
[0009] Based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information, and preset device attack cost and defense cost information, the attacker's net profit information and the defender's total loss information are calculated.
[0010] Based on the net gain information of multiple attackers and the total loss information of defenders, the defense resource allocation information of multiple initial IoT devices is analyzed and calculated to determine the defense resource allocation information of the target IoT device.
[0011] A second aspect of this application provides an IoT device defense resource allocation apparatus, comprising:
[0012] The IoT device information acquisition module is used to acquire IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices.
[0013] The module for calculating device importance representation information and device interaction degree representation information is used to calculate multiple device importance representation information and multiple device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operating status information and communication representation information between IoT devices.
[0014] The module for generating initial IoT device defense resource allocation information and device attack probability information is used to generate multiple initial IoT device defense resource allocation information and multiple device attack probability information.
[0015] The attacker's net gain information and the defender's total loss information calculation module is used to calculate the attacker's net gain information and the defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information and preset device attack cost and defense cost information.
[0016] The target IoT device defense resource allocation information determination module is used to analyze and calculate the initial IoT device defense resource allocation information based on the net gain information of multiple attackers and the total loss information of defenders, and determine the target IoT device defense resource allocation information.
[0017] A third aspect of this application provides a terminal device, the terminal device including a memory and a processor, the memory storing a computer program executable on the processor, and the processor executing the computer program to implement the steps of the IoT device defense resource allocation method described in the first aspect above.
[0018] A fourth aspect of this application provides a computer-readable storage medium, comprising: storing a computer program, wherein when executed by a processor, the computer program implements the steps of the Internet of Things device defense resource allocation method described in the first aspect above.
[0019] Compared with the prior art, the beneficial effects of this application are as follows: This application is used to effectively adapt to the dynamic changes in the topology of the Internet of Things (IoT). It can improve the flexibility and timeliness of allocating defense resources for IoT devices by analyzing and calculating the attack and defense process between attackers and defenders. It can also provide timely and proactive defense against two types of attacks that IoT devices are highly susceptible to: external intrusion and lateral movement. Therefore, compared with the traditional static defense strategy, it is more adaptable to the dynamic changes in the topology and service needs of the IoT, effectively improving the dynamic protection capability of the IoT in dealing with various complex attacks, thereby reducing the losses of IoT devices after being attacked. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment 1 of this application;
[0022] Figure 2 This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment 2 of this application;
[0023] Figure 3 This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment 3 of this application;
[0024] Figure 4This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment 4 of this application;
[0025] Figure 5 This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment 5 of this application;
[0026] Figure 6 This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment Six of this application;
[0027] Figure 7 This is a schematic diagram illustrating the implementation process of the IoT device defense resource allocation method provided in Embodiment 7 of this application;
[0028] Figure 8 This is a schematic diagram of the structure of the IoT device defense resource allocation device provided in Embodiment 8 of this application;
[0029] Figure 9 This is a schematic diagram of the terminal device provided in Embodiment 9 of this application. Detailed Implementation
[0030] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0031] To illustrate the technical solution described in this application, specific embodiments are provided below.
[0032] Figure 1 The implementation flowchart of the IoT device defense resource allocation method provided in Embodiment 1 of this application is shown, and is described in detail below:
[0033] Step S101: Obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication representation information between IoT devices.
[0034] In this embodiment, IoT device identification information can refer to the IoT device's ID information, its MAC address, or registration information obtained by the IoT administrator through a specific communication protocol upon device access. IoT device operational status information refers to dynamic data on the current working status of the IoT device, including online / offline status, resource utilization, battery level, sensor readings, and fault alarms. This can be obtained through operational logs periodically sent by the built-in agent programs of each IoT device to the platform operated by the administrator. IoT topology information refers to network structure data representing the interaction relationships between IoT devices, obtained by abstracting and modeling the interaction relationships using classic graph theory methods. This data can include the organization and connection methods of devices in the network and can be modeled by collecting neighbor information exchanged during real-time collaborative communication between IoT devices. Communication representation information between IoT devices refers to the number of times two IoT devices communicate or the duration of communication between them. This information can be used to measure the closeness between two IoT devices and can be obtained by recording communication messages between two IoT devices using the platform controlled by the IoT administrator.
[0035] Step S102: Based on the IoT device identification information, IoT topology information, IoT device operating status information, and communication characterization information between IoT devices, calculate multiple device importance characterization information and multiple device interaction characterization information.
[0036] In this embodiment, it can be understood that in the IoT topology, each IoT device is considered an IoT device. By acquiring the IoT topology information in real time, combined with the operational status information of each IoT device and the communication representation information between IoT devices, the importance representation information and the interaction representation information corresponding to the identification information of each IoT device are calculated. The importance representation information is used to characterize the overall importance of each IoT device in communication and services, while the interaction representation information is used to characterize the proximity of each IoT device in communicating with other IoT devices within the same IoT topology. It can be understood that when an IoT device is not only a core relay for communication between the vast majority of devices but also provides services to most users in the network, the device can be considered to have high importance; the longer a single IoT device communicates with another IoT device during its online operation, the higher the proximity of that device to the other device.
[0037] In this embodiment, it can be understood that the bottom layer of the Internet of Things (IoT) consists of various types of smart hardware devices, while the upper layer consists of users with the authority to use them. Assume that the IoT includes... A smart hardware device, as IoT devices, they are Each user provides services, and the collection of IoT devices and users is respectively used as... and This indicates that in the Internet of Things (IoT), the interactions between IoT devices change dynamically over time, therefore the network topology also changes dynamically. Assuming from... Start recording the interactions between devices, and... End observation. Set the observation time interval. Divided into a small interval, that is The length of each interval is set to Then the first The intervals are denoted as In a communication network, if the device and In the operating range Memory is interacting, then the device With equipment There are edges between them ,in This represents the set of edges connecting all devices in the network.
[0038] Next, this embodiment will evaluate the importance of IoT devices from two aspects. Firstly, IoT devices act as communication relays, responsible for receiving, processing, and forwarding data packets to extend network coverage and improve communication reliability and efficiency. In the Internet of Things (IoT), the betweenness centrality of an IoT device refers to the number of times that device appears on the shortest communication path between all devices. Devices with high betweenness centrality typically act as critical connection points or relay stations in network communication, and therefore are crucial for the overall operation of the IoT network. Within the interval Inside, equipment The importance of something in the Internet of Things can be measured by the betweenness centrality metric, which is calculated as follows:
[0039]
[0040] in Indicates the operating range Internal device To the equipment The number of shortest paths can be extracted from the IoT topology information. This indicates that these shortest paths pass through devices. Quantity, This is a normalization factor. On the other hand, IoT devices can provide users with diverse services, such as personalized recommendations, remote monitoring, and resource sharing. The more services a device provides to users, the more important it becomes in their lives and work. (Within the operating range) Inside, equipment Importance to the user group can be measured by the following:
[0041]
[0042] in Indicates the operating range Total number of users sending service requests to the Internet of Things. Indicates to the device The number of users who sent service requests.
[0043] In this embodiment, smart devices in the Internet of Things (IoT) not only undertake data communication but also establish direct connections with users and provide various services. These dual functions make them an indispensable part of the IoT ecosystem, thus both aspects can be considered when assessing the importance of the devices. IoT devices In the operating range The comprehensive importance index within the system, which represents the importance of equipment, is denoted as... It can be measured using the following weighting method:
[0044]
[0045] In this embodiment, at the end of each operating interval, the affinity between devices is evaluated based on their recent historical interactions. Indicates in Time device It is online, and Indicates device Offline (sleep or standby); Indicates in Time device With equipment Establish a connection, and This indicates that they are not connected. (In the interval...) At the end, let Indicates recent equipment When in active state with the device The average probability of communication, i.e., the degree of device interaction, characterizes information. This indicator is estimated using the following formula:
[0046]
[0047] in and These represent the start and end points of the historical observation interval considered when calculating intimacy. As a preset value, This indicates that within the historical observation period, the equipment... In active state and with device The duration of the connection; This indicates that within the historical observation period, the equipment... The duration of the active state. Specifically, Indicates device and equipment There was interaction within the historical observation period, and This indicates that there is no interaction between them. (Indicator) The equipment was quantified. For equipment The degree of intimacy; the higher the value of this indicator, the more intimate the device. The more inclined to use equipment Establish communication.
[0048] Step S103: Generate multiple initial IoT device defense resource allocation information and multiple device attack probability information.
[0049] In this embodiment, the initial IoT device defense resource allocation information and the attack probability information of multiple devices can both be randomly generated. This randomization generates the probability of active defense and attack on multiple IoT devices, allowing for iterative filtering to find the defense resource allocation scheme that maximizes the attacker's net gain and minimizes the defender's total loss. This scheme is then used to configure defense resources for IoT devices in the actual IoT topology. IoT device defense resource allocation information refers to the amount of resources (such as computing, storage, and bandwidth resources) allocated to each IoT device for security protection under the current IoT topology. It is understood that increasing the resources allocated to a single IoT device enables a higher level of security detection, thereby improving its defense capabilities and reducing the probability of a successful attack; however, the defense cost also increases accordingly. The attack probability information of multiple devices refers to the probability that each IoT device in the current IoT topology will be attacked, while the attack probability information of a single device refers to the probability that one IoT device in that IoT topology will be attacked.
[0050] Step S104: Based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information, and preset device attack cost and defense cost information, calculate the attacker's net profit information and the defender's total loss information.
[0051] In this embodiment, the preset attack cost information can be manually set, referring to the price information of the hardware devices used by the attacker during online attacks. It is understood that the more hardware devices the attacker uses, the higher the attack cost, and the greater the probability of a successful attack on IoT devices. It is understood that attackers can monitor certain IoT devices deployed in open areas to deduce the importance of these devices. Furthermore, by monitoring the communication between these devices and other IoT devices, attackers can further understand the degree of device interaction. It is understood that an external intrusion attack refers to an attacker initially targeting specific vulnerable IoT devices rather than launching a global attack on all IoT devices; a lateral movement attack refers to an attacker using a controlled IoT device to launch attacks on other IoT devices with which it communicates. For example, in an IoT topology, there are devices 1, 2, and 3 communicating with each other. Communication between devices 1 and 2 is relatively frequent, indicating a high degree of interaction between them. However, communication between devices 1 and 3 is relatively infrequent, indicating a low degree of interaction between them. In this network, device 2 is a common IoT device, while devices 1 and 3 are considered critical devices. Critical devices typically receive more comprehensive and robust protection. A cunning attacker would not directly attack the better-protected devices 1 and 3, but would instead choose the common device 2 as a breakthrough point to launch an external intrusion attack. Then, using device 2 as a springboard, the attacker would leverage the close relationship between the devices to launch a lateral movement attack on devices 1 and 3, thereby expanding the scale of the attack. Defense resource allocation information affects the probability of an attacker's successful attack; the more defense resources deployed, the lower the probability of a successful attack against that device, and the two are inversely proportional. Device importance information determines the attacker's base gain and the defender's base loss; the higher the importance, the greater the attacker's gain after a successful attack, but the greater the defender's loss. Device interaction information affects the success rate of lateral movement attacks; the greater the interaction between devices, the closer the relationship between them, and the higher the success rate of lateral movement. For attackers, the gains from external intrusion and lateral movement attacks are directly proportional to the device's importance and the attacker's probability of success. After deducting the preset attack cost, the attacker's net gain under different attack probabilities is obtained as the attacker's net gain information. For defenders, the losses caused by external intrusion and lateral movement attacks are related to the device's importance, the attacker's probability of success, and the preset defense cost, ultimately resulting in the defender's total loss under different defense resource allocation strategies, which is the defender's total loss information.
[0052] Step S105: Based on the net gain information of multiple attackers and the total loss information of defenders, analyze and calculate the defense resource allocation information of multiple initial IoT devices to determine the defense resource allocation information of the target IoT device.
[0053] In this embodiment, the solution can be based on the equilibrium of a Stackelberg game. Understandably, the total loss information of the defender and the net gain information of the attacker are jointly determined by the defense resource allocation scheme and the attack probability. By constructing an optimization problem with the defense resource allocation vector as the decision variable, the goal is to minimize the total loss function while considering the attacker's optimal response based on the defense strategy. That is, the attacker will adopt the attack probability that maximizes its net gain to carry out external intrusion and lateral movement. This can be achieved by using a genetic algorithm to iteratively search for defense resource allocation strategies, while simultaneously iteratively searching for the attacker's optimal attack probability under that strategy. The corresponding attacker's net gain and defender's total loss are then calculated. Finally, through selection and mutation operations of the genetic algorithm, convergence is achieved to the strategy pair that minimizes the defender's total loss and maximizes the attacker's net gain. The defense resource allocation scheme in this strategy pair is then used as the defense resource allocation information for the target IoT device.
[0054] The IoT device defense resource allocation method provided in this application is designed to effectively adapt to the dynamic changes in IoT topology. By analyzing and calculating the attack and defense process between attackers and defenders, it improves the flexibility and timeliness of allocating IoT device defense resources. It provides timely and proactive defense against external intrusion attacks and lateral movement attacks that IoT devices are highly vulnerable to. Compared with traditional static defense strategies, it is more adaptable to the dynamic changes in IoT topology and effectively enhances the dynamic protection capability of IoT against various complex attacks, thereby reducing the losses of IoT devices after being attacked.
[0055] Figure 2 The flowchart illustrating the implementation of the IoT device defense resource allocation method provided in Embodiment 2 of this application is shown. The difference between this method and Embodiment 1 is that step S102 specifically includes:
[0056] Step S201: Based on the IoT device identification information, IoT topology information, and communication characterization information between IoT devices, calculate multiple device importance characterization information.
[0057] In this embodiment, on the one hand, the identity of IoT devices is first determined using IoT device identification information. Then, a network graph model is constructed based on the IoT topology information. The communication importance of the devices is quantified through betweenness centrality, which is the number of times a device appears on the shortest communication path among all possible devices. The higher the frequency of an IoT device acting as a relay in the communication path, the greater its betweenness centrality index, indicating that the IoT device is more important in the IoT topology. On the other hand, the service importance of IoT devices can be quantified based on user service request data in the communication representation information, such as the frequency of IoT devices providing services to users. This is the ratio of the number of users sending requests to the IoT device to the total number of users; the higher the service coverage, the higher the service importance. Finally, the above communication importance and service importance indices are weighted and summed using pre-set weight values to obtain comprehensive representation information reflecting the importance of each IoT device.
[0058] Step S202: Based on the IoT device identification information, IoT device operating status information, and communication characterization information between IoT devices, calculate the interaction degree characterization information of multiple devices.
[0059] In this embodiment, the identity of the IoT device is first determined using the IoT device identification information. Then, the operational status information of the IoT device is used to determine whether the IoT device is in an active state, and only the communication data of devices in an active state is effectively filtered. Based on the communication characterization information between IoT devices, statistics are compiled on the communication between devices within a specific operating range. In active state and with device The length of time it takes to establish a communication connection, and the device Within this interval, the ratio of this time length to the total activation time length is calculated to obtain the average communication probability between devices. This probability value is the characterization information of the degree of device interaction and is used to quantify the devices. With equipment The frequency of communication between devices; a higher value indicates greater frequency. During communication, the device They exhibit a higher level of intimacy.
[0060] The IoT device defense resource allocation method provided in this application combines IoT device identification information, topology information, operating status information, and communication characterization information to calculate device importance characterization information and device interaction degree characterization information. This enables a quantitative assessment of the communication importance, service importance, and frequency of inter-device interaction of IoT devices, providing data support for subsequent defense resource allocation. It effectively adapts to the dynamic changes in IoT communication topology and business needs, improves the flexibility and timeliness of defense resource allocation, and enhances the proactive defense capability against external intrusion attacks and lateral movement attacks. Compared with the static defense strategies in the prior art, it is better able to cope with complex attack scenarios and reduce the losses of IoT devices after being attacked.
[0061] Figure 3 The flowchart illustrating the implementation of the IoT device defense resource allocation method provided in Embodiment 3 of this application is shown. Its difference from Embodiment 2 described above lies in:
[0062] The communication characterization information between IoT devices includes information on the number of communications between IoT devices;
[0063] Step S201 specifically includes:
[0064] Step S301: Based on the IoT device identification information and IoT topology information, obtain the length information of multiple IoT topology communication paths corresponding to each IoT device identification information.
[0065] In this embodiment, a network graph model is constructed based on the IoT topology information. Each IoT device identification information corresponds to a vertex in the graph, and the physical connections or communication relationships between devices are represented as edges. The weight of each edge can be set as a communication latency or link stability index. Classic graph algorithms, such as Dijkstra's or Floyd-Warshall's algorithms, are used to calculate the shortest path length between any two devices, thus obtaining multiple path length values corresponding to each device identification information. These values reflect the importance of the device's position in the network. For example, the shortest path consumes less time and energy during data transmission; if a device is located on multiple shortest paths, it has a higher relay value in data transmission.
[0066] Step S302: Determine the shortest topology communication path information between IoT devices based on the multiple IoT topology communication path length information corresponding to the IoT device identification information.
[0067] In this embodiment, all possible communication paths corresponding to the device identification information are sorted according to their path length values to determine the specific information of the shortest communication path between devices, including details of all intermediate devices along the path. In particular, if a device is located on the shortest communication path between multiple devices, this indicates that the device is a very important relay device and has a significant impact on the communication of the IoT system.
[0068] Step S303: Based on the shortest topology communication path information between the IoT devices and the communication characterization information between the IoT devices, obtain the device importance characterization information.
[0069] In this embodiment, a device importance representation model is constructed by combining shortest communication path information and communication frequency information. The average frequency of each device's occurrence on the shortest path between all device pairs can be calculated. This indicator reflects the device's importance in communication relay and can serve as a quantification of the device's communication importance. Additionally, by statistically analyzing the number of communications between IoT devices and users, the proportion of service requests received by each device in the total number of requests is calculated. This indicator reflects the urgency of the service demand provided by the device and can serve as a quantification of the device's service importance. The communication importance and service importance are weighted using pre-defined weights to obtain the device importance representation information.
[0070] The IoT device defense resource allocation method provided in this application constructs a network graph model based on IoT topology information, obtains the shortest path between any two devices, identifies key relays in network data communication, and evaluates the communication and service importance of each IoT device by combining the interaction information between users and devices, so that defense resources are tilted towards more important IoT devices.
[0071] Figure 4 The flowchart illustrating the implementation of the IoT device defense resource allocation method provided in Embodiment 4 of this application is shown. Its difference from Embodiment 2 described above lies in:
[0072] The IoT device operating status information includes the IoT device's online duration information;
[0073] The communication characterization information between IoT devices includes communication duration information between IoT devices;
[0074] Step S202 specifically includes:
[0075] Step S401: Based on the IoT device identification information, determine the online duration information of each IoT device and the communication duration information between IoT devices.
[0076] In this embodiment, the online status logs of IoT devices can be collected periodically through the built-in agent program of the IoT devices. Time-series data is then established by combining this data with the IoT device identification information to calculate the total online time of each device within the observation period. Simultaneously, based on communication messages recorded by the IoT administrator platform, the sending and receiving timestamps of the messages are extracted to calculate the duration of each communication between any two devices, and the cumulative communication duration is obtained by aggregating by device pair. For example, by parsing the timestamp field in the message header and combining it with device identification information, a communication duration matrix is constructed. The elements of this matrix represent the cumulative communication duration of two devices within the observation period, and the communication duration information reflects the depth and continuity of the interaction between IoT devices.
[0077] Step S402: Based on the online duration information of the IoT device corresponding to the IoT device and the communication duration information between IoT devices, calculate the interaction degree characterization information of multiple devices.
[0078] In this embodiment, it can be for each IoT device. By using the device With equipment The cumulative communication time between devices divided by the device Online time, in order to quantify the device To the equipment The degree of interaction (i.e., device interaction degree representation information) can be represented as: device interaction degree representation information = communication duration / online duration.
[0079] The IoT device defense resource allocation method provided in this application quantifies device interaction relationships through a dual dimension of online duration and communication duration. It can capture changes in device activity status in real time and dynamically adjust defense resource allocation strategies to cope with the frequent sleep / wake-up characteristics of IoT devices. It accurately identifies high-value communication links by accumulating communication duration rather than simply counting the number of times, prioritizing the protection of devices carrying core services. The intimacy model established based on recent interaction information can more accurately predict the lateral movement paths that attackers may use, deploy defense measures in advance, and focus defense resources on devices with frequent interactions and stable online activity. This avoids excessive investment in low-value or intermittently active devices, significantly improving the accuracy and adaptability of defense resource allocation.
[0080] Figure 5 The flowchart illustrating the implementation of the IoT device defense resource allocation method provided in Embodiment 5 of this application is shown. Its difference from Embodiment 1 described above lies in:
[0081] The multiple device interaction level characterization information includes multiple attackers possessing device interaction level characterization information and multiple defenders possessing device interaction level characterization information;
[0082] Step S104 specifically includes:
[0083] Step S501: Generate a local device interaction degree representation matrix based on the device interaction degree representation information obtained by the multiple attackers.
[0084] In this embodiment, the interaction level characterization information between all IoT devices is sorted by device identifier to construct a complete [system / structure]. 1-order matrix ( (This represents the total number of smart hardware devices in the Internet of Things), forming a global device interaction level representation matrix. ,in Indicates device To the equipment The degree of interaction can be determined by the administrator of the IoT system based on device status information collected by the management platform. Simultaneously, based on the portion of device interaction data that an attacker can actually obtain, corresponding rows and columns are extracted to generate a local device interaction degree representation matrix. This matrix contains only a subset of the non-zero elements from the global matrix, reflecting the attacker's information limitations.
[0085] Step S502: According to the preset matrix decomposition loss calculation function, the local device interaction degree characterization matrix is subjected to matrix decomposition processing to obtain a combination of device characterization feature matrices.
[0086] In this embodiment, the attacker's access is very limited, typically preventing them from directly observing and grasping all the information about the IoT system's operation. In reality, the interaction process between IoT devices exhibits low-rank characteristics. This property stems from the correlation between the spatial distribution and functional attributes of IoT devices, resulting in strong structural features in the interaction patterns. Devices with similar functions often exhibit stronger interactions. Therefore, matrix factorization can be used to predict information and complete missing values based on limited observation data. By reconstructing the latent feature space through dimensionality reduction, accurate modeling of the device interaction degree representation information can be achieved, significantly improving the information completeness in sparse sensing scenarios. In this embodiment, the partial device interaction degree representation information obtainable by the attacker is used as a local device interaction degree representation matrix. The attacker can use this limited local device interaction degree representation information to predict the global device interaction degree representation information. Let the matrix... This represents the true level of intimacy between all devices, i.e., a global device interaction level representation matrix, and the matrix... This represents the partial device-to-device affinity data that an attacker can obtain, i.e., a local device interaction degree representation matrix. Because the attacker possesses very limited information, the data... It only contains This refers to a portion of the data. For attackers, leveraging the low-rank nature of interactions between IoT devices, matrix factorization can help them predict missing affinity data. In matrix factorization, attackers utilize matrices... The information is obtained by decomposing it into two feature matrices. and Then, using the product of these two matrices... To predict missing intimacy data.
[0087] Step S503: Calculate the attacker's global device interaction level representation matrix based on the combination of the device representation feature matrices.
[0088] In this embodiment, if the number of selected features is Then the characteristic matrix , When performing matrix factorization, the characteristic matrix is selected. and Their product approximates the matrix. Therefore, a loss function of the following form is introduced to calculate the matrix factorization loss information:
[0089]
[0090] in It is an indicator function and in It takes the value 1 when it exists and 0 when it is missing; Representation matrix The i-th row, Representation matrix The j-th column; and It is a regularization term that can prevent overfitting. Denotes the Frobenius norm; and It is a hyperparameter that satisfies .
[0091] Product of characteristic matrices The closer to the matrix Then the loss function The smaller the value of , the better. Therefore, the matrix factorization problem is transformed into an optimization problem: how to select the optimal eigenmatrix. and This makes the loss function The value of is the smallest. Let and If the optimal solution to this optimization problem is given, then the final affinity result predicted by the attacker is: .
[0092] Step S504: Calculate the attacker's net profit information based on the attacker's global device interaction degree characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset attack cost information.
[0093] In this embodiment, the attacker's net gain is calculated based on the global interaction matrix predicted by the attacker, combined with initial defense resource allocation information and device attack probability information. Specifically, the attacker's gain comes from two parts: the gain from a successful external intrusion and the gain from a successful lateral movement attack. The external intrusion gain depends on the importance of the target device and the probability of attack success, while the lateral movement gain is related to the importance of the target device, the interaction closeness between the source and target devices (from the attacker's prediction matrix), and the probability of attack success. The attacker's net gain is the total gain minus the attack costs of external intrusion and lateral movement, where the attack cost is proportional to the attack probability. By traversing all matrix decomposition loss information, the set of feature matrix combinations with the minimum loss value can be selected. The product of this set of feature matrices best approximates the local interaction data obtained by the attacker and can be used as the attacker's prediction result of the global interaction level.
[0094] Step S505: Calculate the global device interaction level representation matrix of the defenders based on the device interaction level representation information possessed by the multiple defenders.
[0095] In this embodiment, the defender possesses complete device interaction data and constructs a global device interaction level representation matrix based on the full range of communication records collected by the management platform. This matrix contains real interaction proximity information between all devices, which is compared with the attacker's prediction matrix, reflecting the information asymmetry between the attacker and defender. The defender uses this matrix to assess the actual lateral movement risk, providing accurate data support for subsequent loss calculations.
[0096] One approach is to use a Stackelberg game model, where the product of the device interaction level characteristic matrices is used as the attacker's perceived affinity information. This, combined with defense resource allocation information and attack probability information, calculates the probability of a successful attack on the device. Then, based on the device importance characterization information and attack cost information, the attacker's net gain is calculated. Additionally, based on the global device interaction level characteristic matrix, defense resource allocation information, and attack probability information, the probability of a successful attack on the device is calculated. Finally, based on the device importance characterization information and defense cost information, the defender's total loss is calculated.
[0097] In this embodiment, the confrontation between the attacker and the defender is essentially a game. In network attack and defense scenarios, to more effectively protect system security, the defender must anticipate and predict the attacker's potential intentions and possible countermeasures, and then carefully plan defense strategies to minimize the damage caused by the attack. Therefore, modeling the dynamic process of network attack and defense as a Stackelberg game model is particularly appropriate. First, it is necessary to model the strategies of both the attacker and the defender. For the defender, it needs to deploy defense resources to every device in the network to protect their security. Let... This indicates the defender's defensive strategy, where Indicates the defender is on the device The defensive resources deployed on top. (Order) and These represent the attacker's strategies for external intrusion attacks and lateral movement attacks, respectively. This indicates that the attacker targeted the device. The probability of launching an external intrusion, denoted as the probability of each successful attack using this method, is denoted as... It is related to the defense resources deployed on the device. Inversely proportional, This indicates that the attacker exploited the device. To the equipment The probability of performing a lateral movement, and the probability of each attack succeeding using this method, is denoted as . It is related to the defense resources deployed on the device. Inversely proportional to the equipment For equipment intimacy Proportional.
[0098] Secondly, it is necessary to analyze the utility of both the attacker and the defender. For the attacker, the goal is to maximize their net gain by launching an attack. The attacker's net gain equals the attack gain. Subtract attack costs ,Right now:
[0099] .
[0100] Among the attack benefits Includes benefits generated by external intrusion and the benefits generated by lateral movement , that is
[0101] .
[0102] External Intrusion Benefits With the device The probability of successfully carrying out an external intrusion and the importance of the equipment Proportional, with a proportionality constant of .therefore, The calculation formula is as follows:
[0103] .
[0104] Horizontal movement gains With the device The probability of successfully carrying out an external intrusion Devices that utilize external intrusion To the neighbor of the device Success rate of lateral movement attacks and equipment Importance And are directly proportional, with a proportionality constant of Considering that attackers cannot accurately obtain... Only can be used To approximate the estimate. Therefore, The calculation formula is as follows:
[0105] .
[0106] Attack cost Including the cost of external intrusion attacks and the cost of lateral movement attacks They are directly proportional to the probability of launching an attack, with a proportionality coefficient of 1. The cost of the attack is:
[0107] .
[0108] From the defender's perspective, the goal is to minimize the total damage inflicted by the attacker. Total losses of the defenders Includes defense costs and attack losses Therefore, the defender's total losses can be expressed by the following formula:
[0109] ,
[0110] Among them, defense costs Total defensive resources invested Proportional, with a proportionality constant of ,so Attack losses Including losses from external intrusion and lateral movement loss , that is:
[0111] .
[0112] External intrusion losses With equipment The probability of a successful external intrusion and the importance of the equipment Proportional, with a proportionality constant of .therefore, The calculation formula is as follows:
[0113] .
[0114] Lateral movement loss With equipment The probability of a successful external intrusion Devices that utilize external intrusion To the neighbor of the device Success rate of lateral movement attacks and equipment Importance And are directly proportional, with a proportionality constant of .therefore, The calculation formula is as follows:
[0115] .
[0116] Based on the above analysis, the attack and defense interaction process between the attacker and the defender can be modeled as the Stackelberg game model shown below:
[0117]
[0118] .
[0119] Using triplet Let represent the Stackelberg equilibrium strategy, where The Stackelberg equilibrium strategy, known as the defender, and The Stackelberg equilibrium strategy is known as the attacker's strategy.
[0120] Step S506: Calculate the total loss information of the defender based on the attacker's global device interaction degree characterization matrix, the defender's global device interaction degree characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset defense cost information.
[0121] In this embodiment, the defender's total loss consists of three parts: the cost of defensive resource investment, the loss caused by external intrusion, and the loss caused by lateral movement attacks. The defensive cost is proportional to the total amount of allocated defensive resources; the external intrusion loss depends on the importance of the device and the probability of successful intrusion; the lateral movement loss is calculated based on the actual global interaction matrix, combined with the importance of the target device and the probability of successful lateral movement. By combining these three parts of the loss, the total loss value under different defensive resource allocation strategies is obtained, providing a basis for subsequent optimization decisions.
[0122] The IoT device defense resource allocation method provided in this application constructs a global device interaction degree representation matrix and a local device interaction degree representation matrix. Combining matrix factorization technology, it simulates the attacker's information limitations and predictive behavior, quantifying the attacker's cognitive process in the attack-defense game into a computable matrix factorization problem. This enables the optimization of defense strategies to more accurately address the attacker's actual capability boundaries. By introducing a matrix factorization loss function to filter the optimal attack prediction results, it ensures that the attacker's payoff calculation conforms to the information asymmetry characteristics in real attack-defense scenarios. This method is used to achieve dynamic optimization allocation of defense resources and effectively improve the IoT system's proactive defense capability against unknown attacks.
[0123] Figure 6 The flowchart illustrating the implementation of the IoT device defense resource allocation method provided in Embodiment Six of this application is shown. Its difference from Embodiment Five described above lies in:
[0124] The preset attack cost information includes preset external intrusion cost information and preset lateral movement cost information;
[0125] The probability information of the device being attacked includes the probability information of the device being subjected to external intrusion and the probability information of the device being subjected to lateral movement.
[0126] Step S504 specifically includes:
[0127] Step S601: Based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance characterization information, the attacker's intrusion benefit information is calculated.
[0128] In this embodiment, the amount of defense resources deployed on a device in the defense resource allocation information directly affects the probability of an attacker successfully launching an external intrusion. Generally, the probability of an attacker successfully launching an external intrusion on a device is inversely proportional to the amount of defense resources allocated to that device. The attacker's gain from an external intrusion attack is directly proportional to the product of the device's importance and the probability of successful intrusion. After deducting the product of a preset attack cost and the attack probability, the attacker's net gain from launching an external intrusion attack is obtained.
[0129] Step S602: Based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree representation matrix, and the IoT device's probability of being attacked by lateral movement, the attacker's lateral movement benefit information is calculated.
[0130] In this embodiment, the net gain information of an attacker carrying out a lateral movement attack can be calculated based on the defense resource allocation information deployed by the IoT device, the probability information of the attacker's lateral movement, the combination of device interaction degree characterization feature matrices, device importance characterization information, and preset lateral movement attack cost information. The product of the device interaction degree characterization feature matrices represents the attacker's perceived device intimacy. The probability of an attacker successfully carrying out a lateral movement attack is inversely proportional to the defense resources deployed on the target device and directly proportional to the intimacy of the source device. Calculating the net gain information of a lateral movement attack requires comprehensively considering the importance of the target device, the probability of the source device suffering external intrusion, and the probability of lateral movement to the target device, and then subtracting the preset lateral movement attack cost to finally obtain the net gain information obtained by the attacker through the lateral movement attack.
[0131] Step S603: Calculate the attacker's net profit information based on preset attack cost information, attacker intrusion profit information, and lateral movement profit information.
[0132] In this embodiment, the attacker's total net gain in the complete attack process can be obtained by adding the net gain from external intrusion to the net gain from lateral movement. The attacker's net gain is the sum of the external intrusion gain and the lateral movement gain. By calculating and summing the net gains of the two attack methods separately, the attacker's total net gain in the complete attack chain is obtained. This value reflects the attacker's optimal gain level under a specific defense strategy, providing a reference for defenders to evaluate the effectiveness of their strategies.
[0133] Step S506 specifically includes:
[0134] Step S604: Based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance characterization information, calculate the device defense intrusion loss information.
[0135] In this embodiment, the defender's external intrusion losses are directly proportional to the importance of the device, the probability of external intrusion, and the probability of successful intrusion. The higher the importance of the device, the greater the loss after a successful intrusion; insufficient allocation of defense resources leading to an increased probability of success will also increase losses.
[0136] Step S605: Based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree characterization matrix, the IoT device's probability of being attacked by lateral movement, and the device importance characterization information, calculate the device defense lateral movement loss information.
[0137] In this embodiment, the lateral movement loss is calculated based on the defender's real global interaction matrix, combined with the target device's importance, lateral movement probability, and success probability. The more frequent the interaction between devices (higher intimacy), the higher the probability of successful lateral movement; the more important the target device, the greater the loss.
[0138] Step S606: Calculate the total loss information of the defender based on the preset defense cost information, the global device interaction degree representation matrix of the defender, the device defense intrusion loss information, and the device defense lateral movement loss information.
[0139] In this embodiment, the total loss for the defender is the sum of defense costs, intrusion losses, and lateral movement losses. By calculating the total loss under different defense resource allocation strategies, a quantitative basis is provided for selecting the optimal strategy.
[0140] The IoT device defense resource allocation method provided in this application splits device attack cost information and attack probability information into two attack dimensions: external intrusion and lateral movement. Combined with the attacker's ability to predict proximity, it enables refined calculation of the attacker's multi-stage attack benefits, distinguishes the attack consumption of the two processes of external intrusion and lateral movement, accurately maps costs and benefits, optimizes the allocation efficiency of defense resources under different attacks, improves the dynamic adaptability of defense decisions, and thus enhances the IoT defense system's proactive response capability to complex attack chains.
[0141] Figure 7 The flowchart illustrating the implementation of the IoT device defense resource allocation method provided in Embodiment Seven of this application is shown. The difference between this method and Embodiment One is that step S105 specifically includes:
[0142] Step S701: Determine whether the maximum value of the attacker's net profit information is less than the preset attacker's net profit threshold information; if yes, return to step S103; if no, proceed to step S702.
[0143] In this embodiment, the equipment defense resource allocation information, the probability of external intrusion, and the probability of lateral movement are all pre-set by the defender through automated methods. This information can be randomly generated under the premise of meeting actual application conditions. Subsequently, this information will be dynamically updated to seek the optimal solution. As for the attack cost information, it needs to be set according to the actual situation to ensure the accuracy and feasibility of the solution.
[0144] Step S702: Based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net profit information, the IoT device intrusion attack probability information, the IoT device lateral movement attack probability information, the device importance characterization information, and the preset intrusion attack cost information, the attacker's loss information is calculated.
[0145] In this embodiment, the attacker's gain from external intrusion into the device is directly proportional to the product of the device's importance representation information and the probability information of external intrusion, and inversely proportional to the amount of defense resources allocated to the IoT device; the attacker's cost of external intrusion into the device is directly proportional to the probability information of external intrusion. The attacker's net gain from external intrusion equals the gain from external intrusion minus the cost of external intrusion.
[0146] Step S703: Based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net profit information, the combination of device characterization feature matrices, the probability information of IoT devices being attacked laterally, and the preset cost information of lateral attacks, calculate the lateral attacker loss information.
[0147] In this embodiment, the attacker's prediction of device affinity is represented by the product of the device interaction degree characterization feature matrices. The attacker's gain from lateral movement on a device is directly proportional to the product of the probability information of lateral movement, the affinity between devices, and the target device importance characterization information, and inversely proportional to the amount of defense resources allocated to the IoT device. The attack cost of the attacker's lateral movement on a device is directly proportional to the probability information of lateral movement. The net gain obtained by the attacker from lateral movement equals the gain from lateral movement minus the attack cost of lateral movement. Then, based on the intrusion attacker's loss information and the lateral attacker's loss information, the attacker's loss information is calculated; subsequently, based on the attacker's loss information, the defender's total loss information, and the global device interaction degree characterization matrix, the target IoT device defense resource allocation information is determined.
[0148] In this embodiment, the adjustment of the device's external intrusion probability information and lateral movement probability information is achieved through iterative search using a genetic algorithm.
[0149] In this embodiment, the losses suffered by the defender due to external intrusion attacks on devices are directly proportional to the product of the device importance representation information and the external intrusion probability information, and inversely proportional to the amount of defense resources allocated to the IoT devices. The losses suffered by the defender due to lateral movement attacks on devices are directly proportional to the product of the lateral movement probability information, the proximity between devices, and the target device importance representation information, and inversely proportional to the amount of defense resources allocated to the IoT devices. The defender's defense costs are directly proportional to the amount of defense resources allocated to the IoT devices. The total losses suffered by the defender due to attacks are equal to the sum of the external intrusion losses, lateral movement losses, and defense costs.
[0150] In this embodiment, the adjustment of IoT device defense resource allocation information can be achieved through iterative search using a genetic algorithm. The total loss for the defender can be calculated by combining the IoT device defense resource allocation information, the acquired external intrusion probability information, and the lateral movement probability information. If the total loss reaches its minimum, the iterative search stops; otherwise, the IoT device defense resource allocation information is repeatedly adjusted until the following condition is met: a set of external intrusion probability information, lateral movement probability information, and IoT device defense resource allocation information is found such that if the defender uses this set of defense resource allocation information, the attacker cannot increase the net gain regardless of how they adjust the intrusion probability information and lateral movement probability information; simultaneously, when the attacker chooses this set of intrusion probability information and lateral movement probability information, the defender cannot reduce the total loss regardless of how they adjust the defense resource allocation information. The attacker aims to maximize the net gain, while the defender strives to minimize the total loss. By adjusting the external intrusion probability information, lateral movement probability information, and IoT device defense resource allocation information, the scheme that maximizes the attacker's net gain and minimizes the defender's total loss is selected. Because this scheme can force a rational balance in the strategic interaction between attackers and defenders, the corresponding IoT device defense resource allocation information in this scheme can serve as the best defense strategy for the defenders.
[0151] The IoT device defense resource allocation method provided in this application calculates the attacker's net gain and the defender's total loss, and uses a genetic algorithm to optimize the defense resource allocation strategy. This achieves dynamic blocking of the attack chain and precise control of defense costs, effectively improving the resource allocation efficiency and security protection capability of the IoT system in dynamic attack and defense scenarios.
[0152] Corresponding to the method in the above embodiments, Figure 8 This paper illustrates a structural block diagram of an IoT device defense resource allocation apparatus provided in an embodiment of this application. For ease of explanation, only the parts related to the embodiments of this application are shown. Figure 8 The example IoT device defense resource allocation device can be the execution subject of the IoT device defense resource allocation method provided in the aforementioned embodiment 1.
[0153] Reference Figure 8 The IoT device's defense resource allocation mechanism includes:
[0154] The IoT device information acquisition module 810 is used to acquire IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices.
[0155] The device importance representation information and device interaction degree representation information calculation module 820 is used to calculate multiple device importance representation information and multiple device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operating status information and communication representation information between IoT devices.
[0156] The initial IoT device defense resource allocation information and device attack probability information generation module 830 is used to generate multiple initial IoT device defense resource allocation information and multiple device attack probability information.
[0157] The attacker's net gain information and the defender's total loss information calculation module 840 is used to calculate the attacker's net gain information and the defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information and preset device attack cost and defense cost information.
[0158] The target IoT device defense resource allocation information determination module 850 is used to analyze and calculate the target IoT device defense resource allocation information based on the net gain information of multiple attackers and the total loss information of defenders.
[0159] The process by which each module in the IoT device defense resource allocation device provided in this application implements its respective function can be specifically referred to the foregoing. Figure 1 The description of the illustrated embodiment will not be repeated here.
[0160] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0161] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.
[0162] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0163] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."
[0164] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. It should also be understood that although the terms "first," "second," etc., are used in the text to describe various elements in some embodiments of this application, these elements should not be limited by these terms. These terms are merely used to distinguish one element from another. For example, a first table may be named a second table, and similarly, a second table may be named a first table, without departing from the scope of the various described embodiments. Both the first table and the second table are tables, but they are not the same table.
[0165] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0166] The IoT device defense resource allocation method provided in this application embodiment can be applied to terminal devices such as mobile phones, tablets, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, and personal digital assistants (PDAs). This application embodiment does not impose any restrictions on the specific type of terminal device.
[0167] For example, the terminal device may be a station (S) in a WLAN, a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA) device, a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an in-vehicle device, a vehicle networking terminal, a computer, a laptop computer, a handheld communication device, a handheld computing device, a satellite wireless device, a wireless modem card, a set-top box (STB), customer premises equipment (CPE), and / or other devices used for communication over a wireless system, as well as next-generation communication systems, such as mobile terminals in 5G networks or mobile terminals in future evolved Public Land Mobile Network (PLMN) networks.
[0168] As an example and not a limitation, when the terminal device is a wearable device, the term "wearable device" can also refer to any device that utilizes wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices worn directly on the body or integrated into a user's clothing or accessories. Wearable devices are not merely hardware devices; they achieve powerful functions through software support, data interaction, and cloud interaction. Broadly defined, wearable smart devices include those with comprehensive functions, large sizes, and the ability to perform complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those focused on a specific application function that require interaction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0169] Figure 9This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. For example... Figure 9 As shown, the terminal device 9 of this embodiment includes: at least one processor 90 ( Figure 9 Only one is shown in the image), and a memory 91 stores a computer program 92 that can run on the processor 90. When the processor 90 executes the computer program 92, it implements the steps in the various IoT device defense resource allocation method embodiments described above, for example... Figure 1 Steps S101 to S105 are shown. Alternatively, when the processor 90 executes the computer program 92, it implements the functions of each module / unit in the above-described device embodiments, for example... Figure 8 The functions of modules 810 to 850 are shown.
[0170] The terminal device 9 can be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor 90 and a memory 91. Those skilled in the art will understand that... Figure 9 This is merely an example of terminal device 9 and does not constitute a limitation on terminal device 9. It may include more or fewer components than shown, or combine certain components, or different components. For example, the terminal device may also include input transmission devices, network access devices, buses, etc.
[0171] The processor 90 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0172] In some embodiments, the memory 91 may be an internal storage unit of the terminal device 9, such as a hard disk or memory of the terminal device 9. The memory 91 may also be an external storage device of the terminal device 9, such as a plug-in hard disk, smart media card (SMC), secure digital card (SD), flash card, etc., equipped on the terminal device 9. Furthermore, the memory 91 may include both internal and external storage units of the terminal device 9. The memory 91 is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory 91 can also be used to temporarily store data that has been sent or will be sent.
[0173] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0174] This application also provides a terminal device, which includes at least one memory, at least one processor, and a computer program stored in the at least one memory and executable on the at least one processor. When the processor executes the computer program, it causes the terminal device to implement the steps in any of the above method embodiments.
[0175] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.
[0176] This application provides a computer program product that, when run on a terminal device, enables the terminal device to implement the steps described in the various method embodiments above.
[0177] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0178] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0179] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0180] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0181] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A method for allocating defense resources for Internet of Things (IoT) devices, characterized in that, include: Obtain IoT device identification information, IoT device operating status information, IoT topology information, and communication characteristics between IoT devices; Based on the IoT device identification information, IoT topology information, IoT device operating status information, and communication characterization information between IoT devices, multiple device importance characterization information and multiple device interaction characterization information are calculated. Generate multiple initial IoT device defense resource allocation information and multiple device attack probability information; Based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information, and preset device attack cost and defense cost information, the attacker's net profit information and the defender's total loss information are calculated. Based on the net gain information of multiple attackers and the total loss information of defenders, the defense resource allocation information of multiple initial IoT devices is analyzed and calculated to determine the defense resource allocation information of the target IoT device; The multiple device interaction level characterization information includes multiple attackers possessing device interaction level characterization information and multiple defenders possessing device interaction level characterization information; The step of calculating the attacker's net gain and the defender's total loss based on multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information, and preset attack cost and defense cost information specifically includes: Based on the device interaction level characterization information obtained by the multiple attackers, a local device interaction level characterization matrix is generated. Based on the preset matrix decomposition loss calculation function, the local device interaction degree characterization matrix is subjected to matrix decomposition processing to obtain a combination of device characterization feature matrices; Based on the combination of the device characterization feature matrices, the attacker's global device interaction level characterization matrix is calculated; Based on the attacker's global device interaction degree characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset attack cost information, the attacker's net profit information is calculated. Based on the device interaction level representation information possessed by the multiple defenders, the global device interaction level representation matrix of the defenders is calculated. Based on the attacker's global device interaction level characterization matrix, the defender's global device interaction level characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset defense cost information, the defender's total loss information is calculated.
2. The IoT device defense resource allocation method as described in claim 1, characterized in that, The steps for calculating multiple device importance representation information and multiple device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operating status information, and communication representation information between IoT devices specifically include: Based on the IoT device identification information, IoT topology information, and communication characterization information between IoT devices, multiple device importance characterization information is calculated. Based on the IoT device identification information, IoT device operating status information, and communication characterization information between IoT devices, multiple device interaction degree characterization information is calculated.
3. The IoT device defense resource allocation method as described in claim 2, characterized in that, The communication characterization information between IoT devices includes information on the number of communications between IoT devices; The step of calculating multiple device importance characterization information based on the IoT device identification information, IoT topology information, and communication characterization information between IoT devices specifically includes: Based on the IoT device identification information and IoT topology information, the length information of multiple IoT topology communication paths corresponding to each IoT device identification information is obtained; Based on the length information of multiple IoT topology communication paths corresponding to the IoT device identification information, the shortest topology communication path information between IoT devices is determined; Based on the shortest topology communication path information between the IoT devices and the communication characterization information between the IoT devices, the device importance characterization information is obtained.
4. The IoT device defense resource allocation method as described in claim 2, characterized in that, The IoT device operating status information includes the IoT device's online duration information; The communication characterization information between IoT devices includes communication duration information between IoT devices; The step of calculating the interaction degree characterization information of multiple devices based on the IoT device identification information, IoT device operating status information, and communication characterization information between IoT devices specifically includes: Based on the IoT device identification information, determine the online duration information of each IoT device and the communication duration information between IoT devices; Based on the online duration information of the IoT devices corresponding to the IoT devices and the communication duration information between the IoT devices, the interaction degree characterization information of multiple devices is calculated.
5. The IoT device defense resource allocation method as described in claim 1, characterized in that, The preset attack cost information includes preset intrusion attack cost information and preset lateral movement attack cost information; The probability information of the device being attacked includes the probability information of the IoT device being intruded upon and the probability information of the IoT device being moved laterally. The step of calculating the attacker's net profit information based on the attacker's global device interaction level characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset attack cost information specifically includes: Based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance characterization information, attacker intrusion benefit information is calculated. Based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree characterization matrix, and the IoT device's probability of being attacked by lateral movement, the attacker's lateral movement benefit information is calculated. Based on the preset attack cost information, attacker intrusion profit information, and lateral movement profit information, the attacker's net profit information is calculated. The step of calculating the defender's total loss information based on the attacker's global device interaction level characterization matrix, the defender's global device interaction level characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset defense cost information specifically includes: Based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, and device importance characterization information, the device defense intrusion loss information is calculated. Based on the initial IoT device defense resource allocation information, the attacker's global device interaction degree characterization matrix, the IoT device's probability of being attacked by lateral movement, and the device's importance characterization information, the device defense lateral movement loss information is calculated. Based on the preset defense cost information, the defender's global device interaction degree representation matrix, device defense intrusion loss information, and device defense lateral movement loss information, the defender's total loss information is calculated.
6. The IoT device defense resource allocation method as described in claim 5, characterized in that, The step of analyzing and calculating the defense resource allocation information of multiple initial IoT devices based on multiple attacker net gain information and defender total loss information to determine the defense resource allocation information of the target IoT device specifically includes: Determine whether the maximum value of the attacker's net profit information is less than a preset attacker net profit threshold information; If so, return to the step of generating multiple initial IoT device defense resource allocation information and multiple device attack probability information; If not, the attacker's loss information is calculated based on the initial IoT device defense resource allocation information, IoT device intrusion attack probability information, IoT device lateral movement attack probability information, device importance characterization information, and preset intrusion attack cost information corresponding to the maximum value of the attacker's net profit information. Based on the initial IoT device defense resource allocation information corresponding to the maximum value of the attacker's net profit information, the combination of device characterization feature matrices, the probability information of IoT devices being attacked laterally, and the preset cost information of lateral attacks, the lateral attacker loss information is calculated. The attacker's loss information is calculated based on the intrusion attacker's loss information and the lateral attacker's loss information. Based on the attacker's loss information, the defender's total loss information, and the global device interaction degree representation matrix, the target IoT device defense resource allocation information is determined.
7. A resource allocation device for Internet of Things (IoT) devices, characterized in that, include: The IoT device information acquisition module is used to acquire IoT device identification information, IoT device operating status information, IoT topology information, and communication characterization information between IoT devices. The module for calculating device importance representation information and device interaction degree representation information is used to calculate multiple device importance representation information and multiple device interaction degree representation information based on the IoT device identification information, IoT topology information, IoT device operating status information and communication representation information between IoT devices. The module for generating initial IoT device defense resource allocation information and device attack probability information is used to generate multiple initial IoT device defense resource allocation information and multiple device attack probability information. The attacker's net gain information and the defender's total loss information calculation module is used to calculate the attacker's net gain information and the defender's total loss information based on the initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information and preset device attack cost and defense cost information. The target IoT device defense resource allocation information determination module is used to analyze and calculate the initial IoT device defense resource allocation information based on the net gain information of multiple attackers and the total loss information of defenders, and determine the target IoT device defense resource allocation information. The multiple device interaction level characterization information includes multiple attackers possessing device interaction level characterization information and multiple defenders possessing device interaction level characterization information; The step of calculating the attacker's net gain and the defender's total loss based on multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, device interaction degree characterization information, and preset attack cost and defense cost information specifically includes: Based on the device interaction level characterization information obtained by the multiple attackers, a local device interaction level characterization matrix is generated. Based on the preset matrix decomposition loss calculation function, the local device interaction degree characterization matrix is subjected to matrix decomposition processing to obtain a combination of device characterization feature matrices; Based on the combination of the device characterization feature matrices, the attacker's global device interaction level characterization matrix is calculated; Based on the attacker's global device interaction degree characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset attack cost information, the attacker's net profit information is calculated. Based on the device interaction level representation information possessed by the multiple defenders, the global device interaction level representation matrix of the defenders is calculated. Based on the attacker's global device interaction level characterization matrix, the defender's global device interaction level characterization matrix, multiple initial IoT device defense resource allocation information, device attack probability information, device importance characterization information, and preset defense cost information, the defender's total loss information is calculated.
8. A terminal device, characterized in that, The terminal device includes a memory and a processor. The memory stores a computer program that can run on the processor. When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Defense method and system for integrated energy information physical system
CN118487806A
Game-based optimal resource allocation method for cyber-physical power system (cpps) to defend against false data injection (fdi) attack
GB202218851D0