Method, device and medium for evaluating security policy of internet of things interface

By constructing interface semantics and behavior graphs to simulate attack chains, generating executable programs and monitoring platform responses, the problem of lack of verification for IoT interface security policies is solved, enabling effective evaluation and optimization of interface security policies and improving network transmission security.

CN120785638BActive Publication Date: 2026-05-12NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NO 15 INST OF CHINA ELECTRONICS TECH GRP
Filing Date
2025-08-11
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing IoT interface security strategies lack closed-loop verification and cannot confirm successful attack paths, resulting in insufficient network transmission security.

Method used

By constructing interface semantic graphs and behavioral graphs, attack chains are simulated, attack chain execution programs are generated, policy verification listeners are deployed to monitor platform responses, policy effectiveness judgment data and anomaly scoring data are obtained and analyzed, and the security assessment results of the interface security policy are determined.

Benefits of technology

It enables effective verification of IoT interface security policies, can identify the effectiveness of protection policies in real time, improve network transmission security, and provide policy optimization suggestions, forming a closed-loop framework for attack and defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785638B_ABST
    Figure CN120785638B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method, device, equipment and medium for evaluating an Internet of Things interface security policy, comprising: performing semantic rule mapping on interface application information according to a preset analysis element to obtain an interface semantic graph; constructing an interface state derivation path based on a multi-interface behavior graph; executing a preset graph search algorithm on the interface semantic graph according to the interface state derivation path to construct an attack chain candidate sequence; listening to interface trigger behaviors of an attack chain execution program through a policy verification listener, and determining policy taking effect judgment data according to policy feedback data and preset interception behaviors; determining interface abnormal score data according to execution process return information of the policy verification listener and execution process return information of the attack chain execution program; and determining a security evaluation result of the interface security policy according to the policy taking effect judgment data and the interface abnormal score data. Thus, the security evaluation result of the interface security policy is effectively determined, and network transmission security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this disclosure relate to the field of network security technology, and more specifically, to an evaluation method, apparatus, device, and medium suitable for an Internet of Things (IoT) interface security strategy. Background Technology

[0002] With the large-scale deployment of IoT devices, such as smart home devices, security cameras, and industrial control terminals, they are widely connected to cloud service platforms via protocols like MQTT, HTTP API, CoAP, and LoRa. While this improves intelligence, it also significantly increases the attack surface. "Going to the cloud" is meant to enhance efficiency and scalability, but the accompanying security risks have shifted from local boundaries to cloud interface boundaries. Devices used in lightweight terminals (such as sensors, low-power controllers, and smart home kits) often suffer from poor security configurability due to limited system resources, closed firmware, and delayed updates. Interface abuse is difficult to detect, making them easy targets for attackers. Currently, interface security policies are mainly used as a defense mechanism to ensure secure data transmission through IoT interfaces. However, current defense mechanisms lack closed-loop verification; even after policy deployment, it cannot be confirmed whether the attack path has been successfully defended.

[0003] However, using existing technologies renders the verification strategy ineffective in defending against attacks, thus reducing network transmission security. Summary of the Invention

[0004] The embodiments described herein provide a method, apparatus, device, and medium for evaluating IoT interface security policies, overcoming the aforementioned problems.

[0005] Firstly, based on the content of this disclosure, a method for evaluating IoT interface security strategies is provided, including:

[0006] The interface application information is semantically mapped according to preset analysis elements to obtain an interface semantic graph. The interface application information is obtained from the Internet of Things platform.

[0007] Establish a multi-interface behavior graph, and construct an interface state derivation path based on the multi-interface behavior graph;

[0008] Based on the interface state derivation path, a preset graph search algorithm is performed on the interface semantic graph to construct a candidate sequence of attack chains;

[0009] Generate the attack chain execution program corresponding to the attack chain candidate sequence;

[0010] By deploying a policy verification listening program in a host environment with listening and database write permissions, the program listens for the interface triggering behavior of the attack chain execution program, and determines the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior.

[0011] Obtain the execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program;

[0012] Based on the strategy, verify the return information of the execution process of the monitoring program and the return information of the execution process of the attack chain execution program to determine the interface anomaly score data;

[0013] Based on the policy effectiveness judgment data and the interface anomaly score data, the security assessment result of the interface security policy is determined.

[0014] Secondly, according to the present disclosure, an evaluation device for IoT interface security strategies is provided, comprising:

[0015] The mapping module is used to perform semantic rule mapping on interface application information according to preset analysis elements to obtain an interface semantic graph. The interface application information is obtained from the Internet of Things platform.

[0016] The first construction module is used to establish a multi-interface behavior graph and construct an interface state derivation path based on the multi-interface behavior graph.

[0017] The second construction module is used to perform a preset graph search algorithm on the interface semantic graph based on the path deduced from the interface state in order to construct a candidate sequence of attack chains;

[0018] The generation module is used to generate the attack chain execution program corresponding to the attack chain candidate sequence;

[0019] The first determining module is used to monitor the interface triggering behavior of the attack chain execution program by a policy verification monitoring program deployed in a host environment with listening and database write permissions, and to determine the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior.

[0020] The acquisition module is used to acquire the execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program;

[0021] The second determining module is used to verify the return information of the execution process of the monitoring program and the return information of the execution process of the attack chain execution program according to the strategy, and to determine the interface anomaly score data.

[0022] The third determining module is used to determine the security assessment result of the interface security policy based on the policy effectiveness judgment data and the interface anomaly score data.

[0023] Thirdly, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the evaluation method for the Internet of Things interface security policy as described in any of the above embodiments.

[0024] Fourthly, a computer-readable storage medium is provided, on which a computer program is stored, and when executed by a processor, the computer program implements the steps of the evaluation method for the IoT interface security policy as described in any of the above embodiments.

[0025] The IoT interface security policy evaluation method provided in this application embodiment maps interface application information using semantic rules based on preset analysis elements to obtain an interface semantic graph. The interface application information is obtained from the IoT platform. A multi-interface behavior graph is established, and an interface state deduction path is constructed based on the multi-interface behavior graph. A preset graph search algorithm is executed on the interface semantic graph according to the interface state deduction path to construct an attack chain candidate sequence. An attack chain execution program corresponding to the attack chain candidate sequence is generated. A policy verification listener deployed in a host environment with listening and database write permissions listens to the interface triggering behavior of the attack chain execution program, and determines the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior. The execution process return information of the policy verification listener and the attack chain execution program are obtained. The interface anomaly score data is determined based on the execution process return information of the policy verification listener and the attack chain execution program. The security evaluation result of the interface security policy is determined based on the policy effectiveness judgment data and the interface anomaly score data. In this way, the attack chain execution program simulates the attack chain to launch an attack, and the policy verification listening program listens to the platform response. This allows for the immediate verification of the effectiveness of the current protection policy. Based on the policy effectiveness judgment data and interface anomaly score data, the security assessment result of the interface security policy can be effectively determined, thereby improving network transmission security.

[0026] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more obvious and understandable, specific implementation methods of this application are described below. Attached Figure Description

[0027] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments will be briefly described below. It should be understood that the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure, wherein:

[0028] Figure 1 This is a flowchart illustrating an evaluation method for an IoT interface security strategy provided in this disclosure.

[0029] Figure 2 This is a schematic diagram of the structure of an evaluation device for an IoT interface security strategy provided in this disclosure.

[0030] Figure 3 This is a schematic diagram of the structure of a computer device provided in this disclosure.

[0031] It should be noted that the elements in the attached diagram are schematic and not drawn to scale. Detailed Implementation

[0032] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are also within the scope of protection of this disclosure.

[0033] Unless otherwise defined, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this subject matter pertains. It will be further understood that terms such as those defined in commonly used dictionaries shall be interpreted as having the meaning consistent with their meaning in the context of the specification and in the relevant art, and shall not be interpreted in an idealized or overly formal form unless otherwise explicitly defined herein. As used herein, the statement of “connecting” or “coupling” two or more parts together shall mean that these parts are directly joined together or joined through one or more intermediate components.

[0034] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of the phrase "embodiment" in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0035] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists, A and B exist simultaneously, or B exists. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Terms such as "first" and "second" are only used to distinguish one component (or part of a component) from another component (or another part of a component).

[0036] In the description of this application, unless otherwise stated, "multiple" means two or more (including two), and similarly, "multiple groups" means two or more (including two groups).

[0037] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0038] Figure 1 This is a flowchart illustrating an evaluation method for an IoT interface security policy provided in an embodiment of this disclosure, as shown below. Figure 1 As shown, the specific process of evaluating IoT interface security policies includes:

[0039] S110. Based on the preset analysis elements, perform semantic rule mapping on the interface application information to obtain the interface semantic graph.

[0040] The interface application information is obtained from the IoT platform. This may include, but is not limited to, interface call documentation (such as OpenAPI, Swagger), packet capture data, or encrypted device command streams.

[0041] The preset analysis elements can be interface parameters, authentication methods, and response behaviors. Specifically, semantic annotation and classification mapping can be performed through static interface documentation, packet capture behavior, and runtime feedback. For example, for interface parameters, the function of each field in each interface can be identified (e.g., whether it is userId, deviceId, or permission identifier); the semantic features of the parameters can be classified using OpenAPI / Swaggerparser (e.g., regular expressions, rule tags). For authentication methods, it can be analyzed whether the request requires credentials, such as Token, JWT, or API Key, and whether multiple authentication processes exist; authentication fields can be identified by combining request headers / packet capture data. For response behaviors, it can be analyzed whether different request return values ​​trigger status changes (e.g., "whether binding was successful," "status code is 200 / 403"); clustering and annotation can be performed on the response Status Code and Body structure. When dividing rules, behaviors of the same type can be abstracted and categorized (e.g., "account creation," "permission call," "device control"); NLP (Natural Language Processing) analysis of interface names and verb collocations, or clustering of behavior patterns based on interface call logs.

[0042] S120. Establish a multi-interface behavior graph and construct an interface state derivation path based on the multi-interface behavior graph.

[0043] The multi-interface behavior graph is a structured graph model used to represent the calling patterns, dependencies, and state transitions between interfaces. The multi-interface behavior graph is defined as a graph structure: G = (V, E), where V represents interface nodes (e.g., / login, / setAdmin), and E represents edges (marking state changes or interface transitions after an interface call). The multi-interface behavior graph can construct attack path flowcharts, analyze the dependencies and impacts of interfaces before and after calls, support path reachability analysis (verifying the possibility of attack chains), and provide path weights as input for subsequent graph searches.

[0044] The information sources for establishing the multi-interface behavior graph are the OpenAPI description file (interface path, parameters, return structure), interface sequence call logs (who comes first and who comes last), token lifecycle, permission change location (e.g., obtaining a token after using the login interface, which can be used to control the interface), and state transition data (e.g., interface B can only be called after interface A is successful).

[0045] The interface state derivation path can be used to describe the derivation path of "interface → result state → next interface".

[0046] When constructing interface state deduction paths based on multi-interface behavior graphs, the node and edge information in the multi-interface behavior graphs can be used in conjunction with the context state of interface calls to generate possible state transition paths. By analyzing the dependencies and call order between interfaces, the preconditions and postconditions of each state change can be determined. Interface parameters, return values, and permission changes are incorporated into the state deduction process to ensure the integrity and logical consistency of the path, thereby generating interface state deduction paths.

[0047] S130. Perform a preset graph search algorithm on the interface semantic graph based on the path deduced from the interface state to construct a candidate sequence of attack chains.

[0048] Among them, based on the interface state deduction path, a preset graph search algorithm (such as depth-first search + risk value weight progression) is performed on the interface semantic graph to construct possible attack path combinations, i.e. attack chain candidate sequences.

[0049] In some embodiments, a preset graph search algorithm is performed on the interface semantic graph based on the interface state derivation path to construct a candidate sequence of attack chains, including:

[0050] The graph nodes and edges in the interface semantic graph are analyzed to extract critical path information related to the target interface state. The critical path information is traversed through a preset graph search algorithm to identify a set of candidate sequences that may constitute an attack chain. The path weights are determined based on the interface state, and the attack chain candidate sequences are selected from the set of candidate sequences according to the path weights and constraints.

[0051] For example, the semantic analysis results of the interfaces are transformed into a weighted graph structure. Nodes are defined as interface names (e.g., / register, / getToken), and edges are connected by interface calls, including conditions (requires a 200 status code or a token). Each node and edge is assigned a "risk value" weight; high-risk interfaces, such as admin settings interfaces and asset download interfaces, receive higher weights, derived from CVE data, security rule bases, or expert experience. A Depth-First Search (DFS) or A* search is performed on the graph, aiming to explore the maximum weighted path. Search termination conditions are set (e.g., attack success status), and obviously illegal paths (e.g., insufficient permissions, incorrect status codes) are filtered out based on path weights and constraints, generating a candidate sequence of attack chains.

[0052] For the attack chain [register→login→getToken→setAdmin], the state transitions and dependencies in the search path are recorded, indicating the order of the paths that must be called and the data dependencies (such as obtaining a token). An example of the attack chain can be simulated as follows:

[0053]

[0054] Identify observable backlink behavior indicators at the end of the attack chain (such as whether uploaded data callbacks are received, device status changes, etc.) as the target for strategy judgment.

[0055] Therefore, by using interface dependency graphs and semantic analysis, the system can automatically combine interface paths with attack value, replacing the manual enumeration process and effectively improving the efficiency of attack path implementation.

[0056] S140. Generate the attack chain execution program corresponding to the attack chain candidate sequence.

[0057] The system automatically compiles and executes scripts (Python, Go, Shell, etc.) based on the attack chain candidate sequence to generate an attack chain executable program (Program B). Program B runs in a controlled execution environment, triggering interface sequences sequentially according to time scheduling or by faking user behavior. This includes simulating real user intervals (faking silent behavior), automatically acquiring tokens, executing chained interface calls, and using time scheduling and request randomization to evade WAF (Web Application Firewall) detection. Program B also supports multi-protocol packet sending such as HTTP / MQTT, automatic token renewal, and parameter randomization to avoid rule identification.

[0058] In some embodiments, the attack chain execution program that generates the attack chain candidate sequence includes:

[0059] Parse the attack chain process information corresponding to the attack chain candidate sequence; call the preset function template based on the attack chain process information corresponding to the attack chain candidate sequence to generate the attack chain executable program corresponding to the attack chain candidate sequence.

[0060] For example, attack chain path parsing: parsing JSON-formatted attack chain steps (i.e., attack chain flow information, including: interface URL, parameters, and condition fields for each step); template generation and execution script: defining call function templates for each interface call (supporting Python / Go / Shell); automated parameter injection: dynamically injecting account / device / Token fields from the test dataset, as shown in the following example (pseudocode):

[0061] ----------------------------------------------------------------------------------------------------------response=requests.post(" / login",json={"user":"test","pwd":"123"})

[0062] token=response.json()["token"]

[0063] -------------------------------------------------------------------------------------------------------

[0064] Control flow generation: Generates a complete execution sequence script plus waiting and dependency checks (such as conditional jumps and retry logic); Output script / container image: Output is a .py / .sh file, or packaged into a container image for subsequent scheduling.

[0065] S150. By deploying a policy verification listener in a host environment with listening and database write permissions, the listener monitors the interface triggering behavior of the attack chain execution program, and determines the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior.

[0066] The policy verification listener (Program A) is deployed in a host environment with listening and database write permissions. After Program B executes, Program A listens for any unexpected feedback behavior from the IoT platform (such as SMS notifications, MQTT callbacks, data writes, or control messages generated via Webhook). This includes monitoring whether the system returns unexpected requests or events, such as public network callback requests, abnormal data writes, or unauthorized user changes; comparing interface execution results with the policy list or whitelist; and combining inbound traffic from reverse channels such as webhook, logs, and MQTT to trigger judgments.

[0067] In some embodiments, the policy effectiveness judgment data for determining the interface security policy based on the policy feedback data of the IoT platform in response to the interface-triggered behavior and the preset interception behavior includes:

[0068] The policy feedback data of the IoT platform in response to the interface-triggered behavior is matched with the preset interception behavior. If the policy feedback data of the IoT platform in response to the interface-triggered behavior matches the preset interception behavior, the policy validity judgment data of the interface security policy indicates that the interface security policy is effective. If the policy feedback data of the IoT platform in response to the interface-triggered behavior does not match the preset interception behavior, the policy validity judgment data of the interface security policy indicates that the interface security policy is ineffective.

[0069] For example, for HTTP response types, the policy feedback data includes status codes (200 / 403) and error or exception fields in the response body; for network behavior types, the policy feedback data includes device reconnection, platform call interface (Webhook), and SMS sending; for IoT behavior data types, the policy feedback data includes status change reporting, action command execution, and MQTTtopic push; and for log / monitoring event types, the policy feedback data includes access logs and alarm system logs.

[0070] Preset interception behaviors describe the behaviors that should be intercepted; that is, certain behaviors should not occur if the policy is successfully implemented. For example, unauthorized users should not be able to call `setAdmin`, unbound devices should not be able to send control commands, illegal token requests should be rejected, and exceeding the interface call frequency limit should trigger degradation / disconnection. Examples are as follows:

[0071] -------------------------------------------------------------------------------------------------------

[0072] {

[0073] "interface":" / setDeviceMode",

[0074] "expected":"403Forbidden",

[0075] "actual":"200OK",

[0076] "result": "Policy not blocked"

[0077] }

[0078] -------------------------------------------------------------------------------------------------------

[0079] -------------------------------------------------------------------------------------------------------

[0080] iffeedback_event.matches(expected_block_rule):

[0081] result = "Strategy effective"

[0082] else:

[0083] result = "Strategy failed"

[0084] -------------------------------------------------------------------------------------------------------

[0085] The effectiveness of interface security policies is determined based on policy feedback data from the IoT platform's response to interface-triggered behaviors and preset interception behaviors. Specifically, the logic is to determine whether a policy is effective based on policy feedback data and preset interception behaviors, using criteria such as "Is the return code an interception code?", "Has the system not executed any dangerous behavior?", and "Has a callback not occurred?". Therefore, by using "whether an attack chain endpoint behavior has occurred" as the standard, the system dynamically evaluates whether existing interface policies are intercepted, thus addressing the current rule system's lack of explicit verification.

[0086] S160. Obtain the execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program.

[0087] The information returned during the execution of the policy verification listener may include: interface logs, system return codes, and behavior sequences returned by the policy verification listener during execution; the information returned during the execution of the attack chain execution program may include: interface logs, system return codes, and behavior sequences returned by the attack chain execution program during execution.

[0088] S170. Based on the policy, verify the return information of the execution process of the monitoring program and the return information of the execution process of the attack chain execution program to determine the interface anomaly score data.

[0089] In some embodiments, interface anomaly scoring data is determined based on the return information from the execution process of the policy verification monitoring program and the return information from the execution process of the attack chain execution program, including:

[0090] A behavior discrimination model is trained using a supervised learning model or an unsupervised anomaly detection algorithm. The execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program are input into the behavior discrimination model. The interface anomaly score data is determined based on the output of the behavior discrimination model.

[0091] Among them, supervised learning models or unsupervised anomaly detection algorithms (such as Isolation Forest, LSTM autoencoder, HMM, Transformer-based time series model) can be used to train behavior discrimination models; to achieve generalized recognition of new variant attacks (such as parameter substitution, path mutation) and abnormal behaviors of interface combinations.

[0092] The behavioral discrimination model takes as input the API call sequence (time order, e.g., request1→request2→feedback), request parameters / response status codes (including body, status_code, etc.), and time-series characteristics of program A / B execution (e.g., time interval, call frequency). The output is an anomaly score, attack chain identifier / classification, and whether the policy was violated (Boolean), i.e., API anomaly score data. A higher anomaly score increases the likelihood of uninterrupted or bypassed behavior; the attack chain identifier / classification indicates the type of attack (privilege escalation? information leakage?).

[0093] Therefore, AI algorithms (LSTM / RNN / Transformer) are used to establish a discrimination model for "legitimate interface behavior patterns" and "suspicious attack sequences" to improve generalization recognition capabilities.

[0094] S180. Based on the policy effectiveness judgment data and interface anomaly score data, determine the security assessment result of the interface security policy.

[0095] In some embodiments, the security assessment result of the interface security policy is determined based on policy effectiveness judgment data and interface anomaly scoring data, including:

[0096] Based on the policy effectiveness judgment data and interface anomaly scoring data, determine the attack interception information corresponding to the attack chain candidate sequence; based on the attack interception information corresponding to the attack chain candidate sequence, determine the security assessment result of the interface security policy.

[0097] The attack interception information corresponding to the attack chain candidate sequence can be used to describe the "penetration score" and "interception probability" of the attack chain candidate sequence under the current configuration. For example, if the following attack chain is executed: registration → login → obtain token → set as administrator, program A listens and hears that " / setAdmin" successfully returns a 200 error, and the role change log is triggered. Then the attack chain ID is "ATK001", the attack path (i.e., the attack chain candidate sequence) is " / register→ / login→ / getToken→ / setAdmin", the ML risk score is 0.92, the intercepted behavior should be "reject setAdmin", the actual feedback is successful setting, the "penetration score" is 90%, and the interception probability is 10%. In this state, based on the attack interception information corresponding to the attack chain candidate sequence, the security assessment result of the interface security policy is determined to be policy failure.

[0098] In this embodiment, semantic rules are mapped to interface application information based on preset analysis elements to obtain an interface semantic graph. The interface application information is obtained from the IoT platform. A multi-interface behavior graph is established, and an interface state deduction path is constructed based on the multi-interface behavior graph. A preset graph search algorithm is executed on the interface semantic graph according to the interface state deduction path to construct an attack chain candidate sequence. An attack chain execution program corresponding to the attack chain candidate sequence is generated. A policy verification listener deployed in a host environment with listening and database write permissions listens to the interface triggering behavior of the attack chain execution program, and determines the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior. The execution process return information of the policy verification listener and the execution process return information of the attack chain execution program are obtained. The interface anomaly score data is determined based on the execution process return information of the policy verification listener and the execution process return information of the attack chain execution program. The security assessment result of the interface security policy is determined based on the policy effectiveness judgment data and the interface anomaly score data. In this way, the attack chain execution program simulates the attack chain to launch an attack, and the policy verification listening program listens to the platform response. This allows for the immediate verification of the effectiveness of the current protection policy. Based on the policy effectiveness judgment data and interface anomaly score data, the security assessment result of the interface security policy can be effectively determined, thereby improving network transmission security.

[0099] In some embodiments, it also includes:

[0100] Obtain the security assessment score corresponding to the interface security policy from the security assessment results of the interface security policy; if the security assessment score corresponding to the interface security policy is lower than the preset threshold, generate policy optimization information for the interface security policy based on the behavior discrimination model.

[0101] Among them, strategy optimization information may include: Interface X lacks token verification; the routing path does not have minimum permissions set; and there is a risk in opening the callback interface to the public network.

[0102] This embodiment can provide call sequences and policy analysis suggestions for low-scoring policies, guiding administrators to optimize permission configurations or enhance interface inspection logic, etc., to facilitate timely optimization of interface security policies and achieve a closed loop of attack and defense capabilities: from failure → back connection verification → suggested optimization → policy re-evaluation.

[0103] In summary, this embodiment enhances the ability to identify interface risk chains by constructing an IoT interface behavior chain modeling and attack path simulation mechanism; it forms a closed-loop framework of behavior simulation + execution verification + strategy countermeasures, enhancing the quantifiability and verifiability of IoT cloud protection; it introduces machine learning methods to construct anomaly detection and strategy suggestion models based on communication behavior and API call sequences, improving generalized detection capabilities; it provides an interface attack chain verification mechanism with automatic feedback and protection assessment capabilities, changing the limitations of traditional detection methods that rely on static scanning; and it achieves the joint capability of unified modeling and security assessment of behavioral data from the cloud service side, device side, and network connection layer.

[0104] Specifically, based on a pre-defined interface call graph, a continuous chain of callable interface paths is generated through graph search or semantic reasoning algorithms. This chain satisfies the conditions of permission legitimacy and context dependency, thereby automatically identifying the attack chain logic path and being compatible with interface state transition logic. Application scenario: Constructing destructive interface chain combinations such as register→auth→update→control. Program B simulates the execution of the interface combination attack chain, while program A monitors the target platform or device for any illegal feedback behavior to assess the effectiveness of the current security policy. This forms an execution-monitoring collaborative system, with program A supporting webhook / MQTT callback monitoring, thus establishing an automatic verification closed loop for attack chain behavior. Based on the monitored program-side callback behavior, it determines whether the attack path has penetrated; and combined with the policy configuration status, it automatically marks the policy interception success rate and attack chain risk level: successful connection → high risk, no connection → policy effective; forming a visual output: policy failure report, callback behavior graph, and risk level indicators (high / medium / low). A unified modeling mechanism for multi-protocol interface behavior enables semantic representation and serialization of interface call flows under communication protocols such as MQTT, HTTP, and CoAP. Interfaces are abstracted into stateful call units (RequestNodes), maintaining the state machine of call context relationships, forming a fine-grained and consistent modeling approach across protocols. This overcomes the limitation of traditional API testing tools that can only handle HTTP interfaces. The model determines whether an interface path call belongs to an abnormal attack chain, supporting long-term dependency modeling and mutation attack sequence identification. It is used to detect API call variants, token replay, and abnormal sequence penetration. Compared with traditional rule-based identification, it has generalized identification and signatureless learning capabilities.

[0105] Figure 2 This is a schematic diagram of the structure of an IoT interface security policy evaluation device provided in this embodiment. The IoT interface security policy evaluation device may include:

[0106] The mapping module 210 is used to perform semantic rule mapping on the interface application information according to preset analysis elements to obtain the interface semantic graph. The interface application information is obtained from the Internet of Things platform.

[0107] The first construction module 220 is used to establish a multi-interface behavior graph and construct an interface state derivation path based on the multi-interface behavior graph.

[0108] The second construction module 230 is used to perform a preset graph search algorithm on the interface semantic graph based on the path deduced from the interface state in order to construct a candidate sequence of attack chains.

[0109] The generation module 240 is used to generate the attack chain execution program corresponding to the attack chain candidate sequence.

[0110] The first determining module 250 is used to monitor the interface triggering behavior of the attack chain execution program by a policy verification monitoring program deployed in a host environment with listening and database write permissions, and to determine the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior.

[0111] The acquisition module 260 is used to acquire the execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program.

[0112] The second determining module 270 is used to verify the return information of the execution process of the monitoring program and the return information of the execution process of the attack chain execution program according to the policy, and to determine the interface anomaly score data.

[0113] The third determination module 280 is used to determine the security assessment result of the interface security policy based on the policy effectiveness judgment data and the interface anomaly score data.

[0114] In this embodiment, optionally, the second building module 230 is specifically used for:

[0115] The graph nodes and edges in the interface semantic graph are analyzed to extract critical path information related to the target interface state. The critical path information is traversed through a preset graph search algorithm to identify a set of candidate sequences that may constitute an attack chain. The path weights are determined based on the interface state, and the attack chain candidate sequences are selected from the set of candidate sequences according to the path weights and constraints.

[0116] In this embodiment, optionally, the generation module 240 is specifically used for:

[0117] Parse the attack chain process information corresponding to the attack chain candidate sequence; call the preset function template based on the attack chain process information corresponding to the attack chain candidate sequence to generate the attack chain executable program corresponding to the attack chain candidate sequence.

[0118] In this embodiment, optionally, the first determining module 250 is specifically used for:

[0119] The policy feedback data of the IoT platform in response to the interface-triggered behavior is matched with the preset interception behavior. If the policy feedback data of the IoT platform in response to the interface-triggered behavior matches the preset interception behavior, the policy validity judgment data of the interface security policy indicates that the interface security policy is effective. If the policy feedback data of the IoT platform in response to the interface-triggered behavior does not match the preset interception behavior, the policy validity judgment data of the interface security policy indicates that the interface security policy is ineffective.

[0120] In this embodiment, optionally, the second determining module 270 is specifically used for:

[0121] A behavior discrimination model is trained using a supervised learning model or an unsupervised anomaly detection algorithm. The execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program are input into the behavior discrimination model. The interface anomaly score data is determined based on the output of the behavior discrimination model.

[0122] In this embodiment, optionally, the third determining module 280 is specifically used for:

[0123] Based on the policy effectiveness judgment data and interface anomaly scoring data, determine the attack interception information corresponding to the attack chain candidate sequence; based on the attack interception information corresponding to the attack chain candidate sequence, determine the security assessment result of the interface security policy.

[0124] In this embodiment, optionally, the acquisition module 260 is further configured to acquire the security assessment score corresponding to the interface security policy from the security assessment results of the interface security policy.

[0125] The generation module 240 is also used to generate policy optimization information for the interface security policy based on the behavior discrimination model if the security assessment score corresponding to the interface security policy is lower than a preset threshold.

[0126] The IoT interface security policy evaluation device provided in this disclosure can execute the above method embodiments. Its specific implementation principle and technical effect can be found in the above method embodiments, and will not be repeated here.

[0127] This application also provides a computer device. Please refer to the following for details. Figure 3 , Figure 3 This is a basic structural block diagram of the computer device in this embodiment.

[0128] The computer device includes a memory 310 and a processor 320 that are communicatively connected to each other via a system bus. It should be noted that only a computer device with memory 310 and processor 320 is shown in the figure; however, it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented alternatively. Those skilled in the art will understand that the computer device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0129] Computer devices can include desktop computers, laptops, handheld computers, and cloud servers. These devices allow for human-computer interaction with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0130] The memory 310 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. RAM may include static RAM or dynamic RAM. In some embodiments, the memory 310 may be an internal storage unit of a computer device, such as the hard disk or RAM of the computer device. In other embodiments, the memory 310 may also be an external storage device of the computer device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, or flash card equipped on the computer device. Of course, the memory 310 may include both internal storage units and external storage devices of the computer device. In this embodiment, the memory 310 is typically used to store the operating system and various application software installed on the computer device, such as the program code of the methods described above. Furthermore, the memory 310 may also be used to temporarily store various types of data that have been output or will be output.

[0131] Processor 320 is typically used to perform overall operations of a computer device. In this embodiment, memory 310 is used to store program code or instructions, including computer operation instructions, and processor 320 is used to execute the program code or instructions stored in memory 310 or process data, such as program code that runs the methods described above.

[0132] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus system can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0133] Another embodiment of this application also provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads computer-readable program code stored in the computer-readable medium, enabling the processor to execute the functional actions specified in each step or combination of steps in the above method; and to generate means for implementing the functional actions specified in each block or combination of blocks in the block diagram.

[0134] Computer-readable media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any suitable combination thereof, wherein the memory is used to store program code or instructions, the program code including computer operation instructions, and the processor is used to execute the program code or instructions of the above-described methods stored in the memory.

[0135] The definitions of memory and processor can be found in the description of the foregoing computer device embodiments, and will not be repeated here.

[0136] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0137] In the various embodiments of this application, the functional units or modules can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0138] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0139] In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" as described in this application does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. This application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims listing several means, several units of these means may be embodied by the same item of hardware. The use of "first," "second," and "third," etc., does not indicate any order and these words should be interpreted as names. Unless otherwise specified, the steps in the above embodiments should not be construed as limiting the order of execution.

[0140] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for evaluating IoT interface security strategies, characterized in that, include: The interface application information is semantically mapped according to preset analysis elements to obtain an interface semantic graph. The interface application information is obtained from the Internet of Things platform. The interface semantic graph is a weighted graph structure, where graph nodes represent interface names and graph edges represent connected interface calls containing conditions; each node and edge is assigned a risk value weight. A multi-interface behavior graph is established, and an interface state derivation path is constructed based on the multi-interface behavior graph. The multi-interface behavior graph is a structured graph model used to represent the calling rules, dependencies, and state transition relationships between interfaces. The interface state derivation path is used to describe the derivation path of interface → result state → next interface. Based on the interface state derivation path, a preset graph search algorithm is performed on the interface semantic graph to construct a candidate sequence of attack chains; Generate the attack chain execution program corresponding to the attack chain candidate sequence; By deploying a policy verification listening program in a host environment with listening and database write permissions, the program listens to the interface triggering behavior of the attack chain executor, and determines the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior. Obtain the execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program; Based on the strategy, verify the return information of the execution process of the monitoring program and the return information of the execution process of the attack chain execution program to determine the interface anomaly score data; Based on the policy effectiveness judgment data and the interface anomaly score data, the security assessment result of the interface security policy is determined.

2. The method according to claim 1, characterized in that, The step of performing a preset graph search algorithm on the interface semantic graph based on the path deduced from the interface state to construct a candidate sequence of attack chains includes: Analyze the graph nodes and edges in the interface semantic graph to extract key path information related to the target interface state; The preset graph search algorithm is used to traverse the critical path information and identify a set of candidate sequences that may constitute an attack chain. Based on the interface state, the path weight is determined, and the attack chain candidate sequence is selected from the candidate sequence set according to the path weight and the constraint conditions.

3. The method according to claim 1, characterized in that, The attack chain execution program that generates the attack chain candidate sequence includes: Parse the attack chain process information corresponding to the attack chain candidate sequence; Based on the attack chain process information corresponding to the attack chain candidate sequence, a preset function template is invoked to generate the attack chain execution program corresponding to the attack chain candidate sequence.

4. The method according to claim 1, characterized in that, The policy effectiveness judgment data for determining the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior includes: Match the policy feedback data of the IoT platform in response to the interface-triggered behavior with the preset interception behavior; If the policy feedback data of the IoT platform in response to the interface-triggered behavior matches the preset interception behavior, then the policy validity judgment data of the interface security policy indicates that the interface security policy is effective. If the policy feedback data of the IoT platform in response to the interface-triggered behavior does not match the preset interception behavior, then the policy validity judgment data of the interface security policy indicates that the interface security policy is invalid.

5. The method according to claim 1, characterized in that, The step of verifying the return information of the monitoring program's execution process and the return information of the attack chain execution program according to the strategy, and determining the interface anomaly scoring data, includes: The behavior discrimination model is trained using a supervised learning model or an unsupervised anomaly detection algorithm; The execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program are input into the behavior discrimination model, and the interface anomaly score data is determined based on the output of the behavior discrimination model.

6. The method according to claim 1, characterized in that, The step of determining the security assessment result of the interface security policy based on the policy effectiveness judgment data and the interface anomaly score data includes: Based on the policy effectiveness judgment data and the interface anomaly score data, determine the attack interception information corresponding to the attack chain candidate sequence; Based on the attack interception information corresponding to the candidate attack chain sequence, the security assessment result of the interface security policy is determined.

7. The method according to claim 5, characterized in that, Also includes: Obtain the security assessment score corresponding to the interface security policy from the security assessment results of the interface security policy; If the security assessment score corresponding to the interface security policy is lower than a preset threshold, then policy optimization information for the interface security policy is generated based on the behavior discrimination model.

8. An evaluation device for IoT interface security strategies, characterized in that, include: The mapping module is used to perform semantic rule mapping on interface application information according to preset analysis elements to obtain an interface semantic graph. The interface application information is obtained from the Internet of Things platform. The interface semantic graph is a weighted graph structure, where graph nodes represent interface names and graph edges represent connected interface calls with conditions. Each node and edge is assigned a risk value weight. The first construction module is used to establish a multi-interface behavior graph and construct an interface state derivation path based on the multi-interface behavior graph; the multi-interface behavior graph is a structured graph model used to represent the calling rules, dependencies and state transition relationships between interfaces; the interface state derivation path is used to describe the derivation path of interface → result state → next interface; The second construction module is used to perform a preset graph search algorithm on the interface semantic graph based on the path deduced from the interface state in order to construct a candidate sequence of attack chains; The generation module is used to generate the attack chain execution program corresponding to the attack chain candidate sequence; The first determining module is used to monitor the interface triggering behavior of the attack chain execution program by a policy verification monitoring program deployed in a host environment with listening and database write permissions, and to determine the policy effectiveness judgment data of the interface security policy based on the policy feedback data of the IoT platform in response to the interface triggering behavior and the preset interception behavior. The acquisition module is used to acquire the execution process return information of the policy verification monitoring program and the execution process return information of the attack chain execution program; The second determining module is used to verify the return information of the execution process of the monitoring program and the return information of the execution process of the attack chain execution program according to the strategy, and to determine the interface anomaly score data. The third determining module is used to determine the security assessment result of the interface security policy based on the policy effectiveness judgment data and the interface anomaly score data.

9. A computer device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the evaluation method of the IoT interface security strategy as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When a computer program is executed by a processor, it implements an evaluation method for the IoT interface security policy as described in any one of claims 1 to 7.