Data security monitoring and early warning method based on Internet of Things
By constructing a device behavior fingerprint database and a cross-domain tactical association rule database, and combining graph neural networks and Bayesian models, the problem of decreased detection accuracy in IoT data security monitoring and early warning methods is solved. This achieves efficient attack chain identification and accurate anomaly detection, and is applicable to IoT security monitoring in smart homes, industrial automation, and critical infrastructure.
Patent Information
- Application Number
- CN202510964094.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-11-14
AI Technical Summary
Existing IoT data security monitoring and early warning methods cannot effectively transform strategic-level attack knowledge into device-level detection capabilities, resulting in decreased detection accuracy, difficulty in correlating device-level anomalies with sudden changes in network traffic, and a high rate of missed detection for cross-domain attacks.
By constructing a device behavior fingerprint database and a cross-domain tactical association rule database, and using graph neural networks to analyze the spatiotemporal correlation of attack path graphs, and combining Bayesian models to quantify threat confidence, we can achieve the identification and anomaly detection of multi-stage attack chains.
It improves the accuracy of data security monitoring and early warning, shortens the APT attack detection time from hours to minutes, reduces the false negative rate of cross-domain attacks, improves detection accuracy, and meets data privacy protection requirements.
Smart Images

Figure CN120956448A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security monitoring technology, and in particular to a data security monitoring and early warning method based on the Internet of Things. Background Technology
[0002] With the widespread application of IoT technology in smart homes, industrial automation, critical infrastructure and other fields, the massive interconnection and data sharing of IoT devices have brought serious data security challenges.
[0003] In existing technologies, IoT data security monitoring and early warning methods rely on static detection based on rule engines. Due to the heterogeneity of devices and resource limitations, they cannot transform strategic-level attack knowledge into device-level detection capabilities. They also cannot correlate device-level anomalies with network traffic mutations to build a full-link attack view, resulting in a decrease in detection accuracy. Summary of the Invention
[0004] This invention provides a data security monitoring and early warning method based on the Internet of Things (IoT) to address the technical problem of how to improve existing data security monitoring and early warning methods, thereby enhancing the accuracy of data security monitoring and early warning.
[0005] To address the aforementioned technical problems, embodiments of the present invention provide a data security monitoring and early warning method based on the Internet of Things, comprising:
[0006] Obtain the real-time operating characteristics of the target IoT device, and construct a device behavior fingerprint database based on the real-time operating characteristics;
[0007] A five-tuple ontology model is constructed based on the device behavior fingerprint database, and a general tactical framework is mapped to the IoT device operation scenario according to the five-tuple ontology model to generate a cross-domain tactical association rule library.
[0008] The multi-source interaction data between the target IoT device and the external environment is parsed and processed according to the cross-domain tactical association rule base, and an attack path map is constructed based on the parsed multi-source interaction features.
[0009] The attack path map is input into a pre-built graph neural network model to obtain a multi-stage attack chain. The persistent threat attack chain in the multi-stage attack chain is identified and its confidence score is calculated.
[0010] Based on the confidence score, anomaly detection is performed on the original network traffic data corresponding to the persistent threat attack chain, and an anonymized early warning analysis report is generated.
[0011] As one preferred embodiment, the step of constructing a five-tuple ontology model based on the device behavior fingerprint database, and mapping a general tactical framework to the IoT device operation scenario according to the five-tuple ontology model to generate a cross-domain tactical association rule library includes:
[0012] Based on ontology modeling language, a five-tuple element and relationship of attacker, device, vulnerability, attack behavior and impact are defined to construct a five-tuple ontology model. The device behavior fingerprint database is used to provide device operation characteristics as a verification benchmark for the five-tuple ontology model.
[0013] Based on the aforementioned five-tuple ontology model, the tactical phases of the general tactical framework are associated with the operational scenarios of IoT devices to generate a device-level attack scenario knowledge base.
[0014] Based on natural language processing technology, attack method-affected device association pairs are extracted from the device-level attack scenario knowledge base as executable rules to generate a cross-domain tactical association rule base.
[0015] As one preferred embodiment, the multi-source interactive data includes device operation logs and raw network traffic;
[0016] The step of parsing and processing the multi-source interaction data between the target IoT device and the external environment based on the cross-domain tactical association rule base, and constructing an attack path graph based on the parsed multi-source interaction features, includes:
[0017] The device operation logs and the raw network traffic are parsed according to protocols, and the data obtained from the protocol parsing is aligned with geographical coordinates according to a unified time base to generate a structured event stream;
[0018] Based on device type, pre-set vulnerability database and general tactical framework, the tactical phase sets the relationship between graph nodes and edges to construct an initial attack path graph that supports dynamic reasoning.
[0019] The structured event stream is mapped to the initial attack path graph, and the real-time running features are injected into the graph nodes. Spatiotemporal weights are added to the edges to generate the attack path graph.
[0020] As one preferred embodiment, the step of inputting the attack path graph into a pre-constructed graph neural network model to obtain a multi-stage attack chain, identifying persistent threat attack chains within the multi-stage attack chain, and calculating their confidence scores includes:
[0021] Based on the pre-built graph neural network model, the spatiotemporal correlation of node features and edge relationships in the attack path graph is analyzed to identify abnormal paths across devices and protocols.
[0022] Based on the abnormal path, a multi-stage attack chain conforming to the attack logic is output;
[0023] The confidence level of the multi-stage attack chain as a persistent threat attack chain is calculated using a Bayesian probability model, and then classified according to a preset confidence level rule to obtain the confidence score of the persistent threat attack chain.
[0024] As one preferred embodiment, the step of performing anomaly detection on the original network traffic data corresponding to the persistent threat attack chain based on the confidence score and generating an anonymized early warning analysis report includes:
[0025] Based on the confidence score, a target anomaly detection model is selected, the original network traffic data is input into the target anomaly detection model, and a list of anomaly events is output.
[0026] Multi-factor risk weights are set, and the risk score of each abnormal event in the list of abnormal events is calculated by risk quantification. The risk level of each abnormal event is then evaluated according to a preset risk rule threshold.
[0027] Based on the abnormal events and their corresponding risk levels, a standardized report is generated. The standardized report is then encrypted using an algorithm to generate an anonymous early warning analysis report.
[0028] Another embodiment of the present invention provides a data security monitoring and early warning system based on the Internet of Things, comprising:
[0029] The acquisition module is used to acquire the real-time operating characteristics of the target IoT device and construct a device behavior fingerprint database based on the real-time operating characteristics;
[0030] The construction module is used to construct a five-tuple ontology model based on the device behavior fingerprint library, and to map the general tactical framework to the IoT device operation scenario according to the five-tuple ontology model, thereby generating a cross-domain tactical association rule library.
[0031] The parsing module is used to parse and process the multi-source interaction data between the target IoT device and the external environment according to the cross-domain tactical association rule base, and construct an attack path map based on the parsed multi-source interaction features;
[0032] The identification module is used to input the attack path map into a pre-built graph neural network model to obtain a multi-stage attack chain, identify the persistent threat attack chain in the multi-stage attack chain and calculate its confidence score.
[0033] The generation module is used to perform anomaly detection on the original network traffic data corresponding to the persistent threat attack chain based on the confidence score, and generate an anonymized early warning analysis report.
[0034] As one preferred embodiment, the construction module is specifically used for:
[0035] Based on ontology modeling language, a five-tuple element and relationship of attacker, device, vulnerability, attack behavior and impact are defined to construct a five-tuple ontology model. The device behavior fingerprint database is used to provide device operation characteristics as a verification benchmark for the five-tuple ontology model.
[0036] Based on the aforementioned five-tuple ontology model, the tactical phases of the general tactical framework are associated with the operational scenarios of IoT devices to generate a device-level attack scenario knowledge base.
[0037] Based on natural language processing technology, attack method-affected device association pairs are extracted from the device-level attack scenario knowledge base as executable rules to generate a cross-domain tactical association rule base.
[0038] As one preferred embodiment, the multi-source interactive data includes device operation logs and raw network traffic;
[0039] The parsing module is specifically used for:
[0040] The device operation logs and the raw network traffic are parsed according to protocols, and the data obtained from the protocol parsing is aligned with geographical coordinates according to a unified time base to generate a structured event stream;
[0041] Based on device type, pre-set vulnerability database and general tactical framework, the tactical phase sets the relationship between graph nodes and edges to construct an initial attack path graph that supports dynamic reasoning.
[0042] The structured event stream is mapped to the initial attack path graph, and the real-time running features are injected into the graph nodes. Spatiotemporal weights are added to the edges to generate the attack path graph.
[0043] As one preferred embodiment, the identification module is specifically used for:
[0044] Based on the pre-built graph neural network model, the spatiotemporal correlation of node features and edge relationships in the attack path graph is analyzed to identify abnormal paths across devices and protocols.
[0045] Based on the abnormal path, a multi-stage attack chain conforming to the attack logic is output;
[0046] The confidence level of the multi-stage attack chain as a persistent threat attack chain is calculated using a Bayesian probability model, and then classified according to a preset confidence level rule to obtain the confidence score of the persistent threat attack chain.
[0047] As one preferred embodiment, the generation module is specifically used for:
[0048] Based on the confidence score, a target anomaly detection model is selected, the original network traffic data is input into the target anomaly detection model, and a list of anomaly events is output.
[0049] Multi-factor risk weights are set, and the risk score of each abnormal event in the list of abnormal events is calculated by risk quantification. The risk level of each abnormal event is then evaluated according to a preset risk rule threshold.
[0050] Based on the abnormal events and their corresponding risk levels, a standardized report is generated. The standardized report is then encrypted using an algorithm to generate an anonymous early warning analysis report.
[0051] Compared with the prior art, the beneficial effects of the embodiments of the present invention are at least one of the following:
[0052] This invention achieves a semantic mapping between "strategic-level attack knowledge and device-level detection capability" by constructing a device behavior fingerprint database and a cross-domain tactical association rule database, thus solving the problem of disconnect between attack intent and device operation in traditional solutions. By utilizing graph neural networks to analyze the spatiotemporal correlation of attack path graphs, the APT attack detection time is reduced from hours to minutes. Furthermore, by quantifying threat confidence through a Bayesian model, the accuracy of multi-stage attack chain identification is improved by over 40%. Simultaneously, through protocol parsing and spatiotemporal alignment techniques, device operation logs and raw network traffic are integrated to construct a full-link attack view, effectively solving the problem of high false negative rates for cross-domain attacks in existing technologies. Attached Figure Description
[0053] Figure 1 This is a flowchart illustrating a data security monitoring and early warning method based on the Internet of Things in one embodiment of the present invention;
[0054] Figure 2 This is a schematic diagram of an IoT-based data security monitoring and early warning system in one embodiment of the present invention.
[0055] Figure label:
[0056] Among them, 11. Acquisition module; 12. Construction module; 13. Parsing module; 14. Recognition module; 15. Generation module. Detailed Implementation
[0057] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0058] In the description of this application, the terms "first," "second," "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first," "second," "third," etc., may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0059] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to the internal communication between two components. The terms "vertical," "horizontal," "left," "right," "upper," "lower," and similar expressions used herein are for illustrative purposes only and do not indicate or imply that the device or component referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as limiting the invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0060] In the description of this application, it should be noted that, unless otherwise defined, all technical and scientific terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this specification is for the purpose of describing specific embodiments only and is not intended to limit the invention. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0061] One embodiment of the present invention provides a data security monitoring and early warning method based on the Internet of Things. For details, please refer to [link / reference]. Figure 1 , Figure 1 The diagram shown is a flowchart of a data security monitoring and early warning method based on the Internet of Things (IoT) according to one embodiment of the present invention, which includes steps S1-S5:
[0062] S1: Obtain the real-time operating characteristics of the target IoT device, and construct a device behavior fingerprint database based on the real-time operating characteristics;
[0063] It should be noted that by collecting IoT device operating characteristics in real time through edge nodes, including CPU power consumption, firmware startup sequence, and wireless signal pulse interval, a unique device behavior fingerprint is generated, which solves the problem of easy MAC address forgery and realizes trusted device identity authentication.
[0064] S2: Construct a five-tuple ontology model based on the device behavior fingerprint database, and map the general tactical framework to the IoT device operation scenario according to the five-tuple ontology model to generate a cross-domain tactical association rule library;
[0065] It should be noted that the device behavior fingerprint database, as the core input source, dynamically records the device's operational characteristics, defining a baseline for legitimate behavior. Building an association rule base based on this database ensures that attack detection rules align with the actual operational context of the device, avoiding false positives caused by device heterogeneity in traditional rule bases, and providing a device-level operational characteristic verification benchmark for attack path inference.
[0066] Cross-domain tactical mapping transforms the tactical phases of general attack tactical frameworks (such as MITREATT&CK) into executable rules for IoT device operation scenarios through ontology modeling. Specifically, it extracts behavioral logic from attack tactics (such as lateral movement and privilege escalation) and maps it to protocol instruction sequences or user behavior trajectories in device operation logs, forming a rule base of association between "attack intent" and "device operation," thus realizing the transformation of strategic-level offensive and defensive knowledge into device-level detection capabilities.
[0067] By constructing an association rule base through cross-domain tactical mapping, dynamic association analysis of cross-device and cross-protocol attack behaviors can be achieved, improving the accuracy and real-time performance of attack chain reasoning. Through anonymized data generation, security intelligence sharing and collaborative response among multiple organizations can be supported while ensuring data privacy, and it can cover more than 90% of MITREATT&CK (Chinese name "Adversarial Tactics, Techniques and Common Sense", which serves as a threat modeling model and knowledge base reflecting attack behaviors at various attack lifecycles) attack vectors.
[0068] Preferably, in one embodiment of the present invention, the step of constructing a five-tuple ontology model based on the device behavior fingerprint database, and mapping a general tactical framework to the IoT device operation scenario according to the five-tuple ontology model to generate a cross-domain tactical association rule base includes:
[0069] S21: Based on the ontology modeling language, the five-tuple elements and relationships of attacker, device, vulnerability, attack behavior and impact are set to construct a five-tuple ontology model. The device behavior fingerprint database is used to provide device operating characteristics as the verification benchmark of the five-tuple ontology model.
[0070] S22: Based on the five-tuple ontology model, associate the tactical phases of the general tactical framework with the operation scenarios of IoT devices to generate a device-level attack scenario knowledge base;
[0071] S23: Based on natural language processing technology, extract the attack method-affected device association pairs from the device-level attack scenario knowledge base as executable rules to generate a cross-domain tactical association rule base.
[0072] Specifically, S21 uses ontology modeling languages such as OWL or RDF to set up a five-tuple element of attacker, device, vulnerability, attack behavior and impact, clearly defining the attributes of each element (such as the attacker's attack method, the device's firmware version, etc.) and their interrelationships (such as the attacker launching an attack by exploiting a vulnerability), and constructs a five-tuple ontology model. At the same time, it uses the device operating characteristics (such as CPU power consumption, firmware startup sequence) in the device behavior fingerprint database as a verification benchmark to ensure that the model is consistent with the actual operating state of the device.
[0073] Based on the five-tuple ontology model, S22 semantically maps tactical phases (such as lateral movement and privilege escalation) of general tactical frameworks such as MITREATT&CK to IoT device operation scenarios (such as PLC command interaction and firmware upgrade). For example, it maps the "privilege escalation" tactical phase to the "unauthorized firmware upgrade command" operation in the device log, thereby generating a device-level attack scenario knowledge base containing the correspondence between tactical phases and device operations.
[0074] S23 uses natural language processing technology to analyze the device-level attack scenario knowledge base. It extracts "attack method-affected device" association pairs (such as "SQL injection-industrial server") through algorithms such as named entity recognition and relation extraction, and transforms them into structured executable rules, such as "if device A has vulnerability B and attack method C is detected, then trigger an alert". Finally, it generates a cross-domain tactical association rule base, realizing the transformation of strategic-level attack knowledge into device-level detection rules.
[0075] It should be noted that the device behavior fingerprint database continuously records device operational characteristics, providing dynamic data input for device operation scenario logs, enabling precise correlation between attack tactics and real-time device behavior. Furthermore, during the automated rule verification phase, historical operational characteristics from the device behavior fingerprint database are used as a benchmark to test whether new rules trigger false alarms under normal behavioral scenarios. If a rule generates an alarm for legitimate behavior in the fingerprint database, it is deemed invalid and removed.
[0076] S3: Based on the cross-domain tactical association rule base, the multi-source interaction data between the target IoT device and the external environment is parsed and processed, and an attack path map is constructed based on the parsed multi-source interaction features.
[0077] Specifically, multi-source interaction feature extraction includes:
[0078] Equipment layer: Analyze PLC (Programmable Logic Controller) operation logs and extract the frequency of abnormal commands;
[0079] Network layer: Capture TCP / UDP (Transmission Control Protocol / User Datagram Protocol) traffic based on DPDK (Data Plane Development Kit) and analyze abnormal protocol distribution.
[0080] User level: Analyze the geographical location jumps in VPN (Virtual Private Network) login logs.
[0081] Preferably, in one embodiment of the present invention, the multi-source interactive data includes at least device operation logs and raw network traffic;
[0082] The step of parsing and processing the multi-source interaction data between the target IoT device and the external environment based on the cross-domain tactical association rule base, and constructing an attack path graph based on the parsed multi-source interaction features, includes:
[0083] S31: Perform protocol parsing on the device operation log and the raw network traffic, and align the data obtained from the protocol parsing with the geographic coordinates according to a unified time base to generate a structured event stream;
[0084] S32: Based on device type, preset vulnerability database and general tactical framework, the tactical phase sets the relationship between graph nodes and edges to construct an initial attack path graph that supports dynamic reasoning;
[0085] S33: Map the structured event stream to the initial attack path graph, inject the real-time running features into the graph nodes, and add spatiotemporal weights to the edges to generate the attack path graph.
[0086] Specifically, multi-source interaction feature extraction covers the device layer, network layer, and user layer. The device layer parses PLC operation logs to extract the frequency of abnormal instructions. The network layer uses DPDK to capture TCP / UDP traffic and count protocol distribution anomalies. The user layer analyzes the geographical location jumps in VPN login logs.
[0087] In S31, the device operation logs and raw network traffic are parsed according to protocols. The time stamp is synchronized by NTP and the device GPS coordinates are combined with the network topology to achieve spatiotemporal reference alignment, generating a structured event stream containing fields such as event ID, device ID, timestamp, geographic coordinates, protocol type, anomaly type and severity.
[0088] S32, based on device type, pre-defined vulnerability database, and general tactical framework, sets up a graph structure with devices, vulnerabilities, and attack behaviors as nodes and attack relationships as edges to construct an initial attack path graph that supports dynamic reasoning.
[0089] S33 maps the structured event stream to the initial graph, injects real-time operating characteristics such as CPU power consumption into nodes, and adds spatiotemporal weights to edges that reflect the attack time interval and spatial correlation, thereby generating an attack path graph containing multi-source interaction characteristics.
[0090] S4: Input the attack path map into a pre-built graph neural network model to obtain a multi-stage attack chain, identify the persistent threat attack chain in the multi-stage attack chain and calculate its confidence score.
[0091] Preferably, in one embodiment of the present invention, the step of inputting the attack path map into a pre-constructed graph neural network model to obtain a multi-stage attack chain, identifying persistent threat attack chains in the multi-stage attack chain, and calculating their confidence scores includes:
[0092] S41: Analyze the spatiotemporal correlation of node features and edge relationships in the attack path graph based on the pre-built graph neural network model to identify abnormal paths across devices and protocols;
[0093] S42: Output a multi-stage attack chain that conforms to the attack logic based on the abnormal path;
[0094] S43: Calculate the confidence level of the multi-stage attack chain as a persistent threat attack chain using a Bayesian probability model, and classify it according to a preset confidence level rule to obtain the confidence score of the persistent threat attack chain.
[0095] Specifically, in this embodiment, the attack path graph is input into a pre-built graph neural network model, and multi-stage attack chain identification and confidence calculation are achieved through the following steps:
[0096] S41 utilizes graph neural network models (such as GCN or GAT) to analyze the spatiotemporal correlation between node features (devices, vulnerabilities, attack behaviors, etc.) and edges (attack relationships) in the graph. Through node embedding technology, it transforms attributes such as device operating characteristics and vulnerability severity into high-dimensional vectors. Combined with the spatiotemporal weights of edges (such as attack time intervals and spatial location correlations), it identifies abnormal paths across devices (such as lateral movement from PLC to server) and across protocols (such as the correlation between Modbus protocol anomalies and TCP traffic mutations). This process captures hidden correlation patterns in the graph structure through multi-layer graph convolution operations. Compared with traditional machine learning models, it can more effectively handle heterogeneous network topologies in the Internet of Things environment.
[0097] Based on the identified abnormal paths, S42 combines discrete abnormal paths into a coherent multi-stage attack chain according to the attack logic of common tactical frameworks such as MITREATT&CK (e.g., the phase sequence of "initial access - privilege escalation - lateral movement - data leakage"). Through time series sorting and attack method correlation analysis (such as the exploit toolchain used by the same attacker), it ensures that the attack chain conforms to the logical coherence of the actual attack scenario.
[0098] S43 utilizes a Bayesian probability model, taking evidence from each stage of the attack chain (such as the duration of the abnormal path, the complexity of the attack method, and the coordination of cross-device attacks) as input to update the prior probability and calculate the confidence level that the attack chain is a persistent threat (APT). For example, if the attack chain contains more than three cross-domain attack stages and lasts for more than 24 hours, the confidence level is increased by 20%. At the same time, it is classified according to preset level rules (such as confidence level ≥80% for high risk and 50%-80% for medium risk), and outputs a confidence score containing the threat probability of each stage, providing a quantitative basis for subsequent anomaly detection.
[0099] S5: Based on the confidence score, perform anomaly detection on the original network traffic data corresponding to the persistent threat attack chain, and generate an anonymized early warning analysis report.
[0100] Preferably, in one embodiment of the present invention, the step of performing anomaly detection on the original network traffic data corresponding to the persistent threat attack chain based on the confidence score and generating an anonymized early warning analysis report includes:
[0101] S51: Select a target anomaly detection model based on the confidence score, input the original network traffic data into the target anomaly detection model, and output a list of anomaly events;
[0102] Specifically, when selecting anomaly detection models with different sensitivities, for example, a high-sensitivity deep learning model (such as a deep neural network) can be used when the confidence level is higher than 80%, and a lightweight and fast detection model (such as a decision tree) can be switched when the confidence level is lower, thus balancing detection accuracy and computational resource consumption.
[0103] Newly identified anomaly features are used as incremental data input into the model, and online learning technology is used to dynamically adjust model parameters (such as neural network weights). This eliminates the need for full data retraining, allowing the model to continuously adapt to new attack methods and improve detection timeliness.
[0104] Meanwhile, before the traffic characteristics are input into the model, small disturbances (such as simulating the behavior of attackers tampering with data packets) are automatically injected to test the stability of the model output. Abnormal events that are sensitive to disturbances are marked as "suspected adversarial attacks" and trigger a manual review process to reduce the false alarm rate.
[0105] Multiple anomaly detection models (such as time-series models and graph models) run in parallel. The models are weighted and voted on based on the confidence levels of their outputs to comprehensively determine the authenticity of anomalies, avoiding missed or false alarms caused by the bias of a single model. Real-time statistics are maintained on model detection accuracy, response latency, and other metrics. When these metrics fall below preset thresholds (e.g., accuracy <90% or latency >500ms), an alarm is automatically triggered and a backup model is switched to ensure high availability of the detection service.
[0106] S52: Set multi-factor risk weights, calculate the risk score of each abnormal event in the abnormal event list through risk quantification, and evaluate the risk level of each abnormal event according to the preset risk rule threshold;
[0107] In this embodiment, multi-factor risk weights are set, risk scores for each abnormal event are calculated through risk quantification, and risk levels are assessed according to preset risk rule thresholds, including:
[0108] S521: Employs a causal reasoning algorithm to analyze the causal relationship between risk factors and historical attack events, dynamically generating non-subjective dynamic weights.
[0109] Specifically, by using causal discovery algorithms (such as causal inference based on conditional independence) to analyze the causal relationships between risk factors (such as "data leakage caused by protocol anomalies"), dynamic weights that are not subjectively assigned are automatically generated to replace traditional manual weighting based on experience, thereby improving the objectivity of the assessment.
[0110] S522. Dynamically adjust the weights according to the current stage of the attack chain, load the parameters of the pre-trained risk assessment model from similar scenarios using transfer learning, and fine-tune the training using new scenario data.
[0111] For example, the weights are dynamically adjusted according to the current stage of the attack chain (including initial access, lateral movement, and data leakage)—the weight of "abnormal communication between devices" is increased to 60% during the lateral movement stage, and the weight of "external connection protocol risk" is strengthened to 50% during the data leakage stage, ensuring that the risk calculation is consistent with the attack evolution logic.
[0112] S523. Use a risk assessment model to score abnormal events, and dynamically divide risk level thresholds based on real-time attack distribution, outputting the risk score and risk level of the current abnormal event.
[0113] Specifically, the dynamic classification of risk level thresholds can follow the following hierarchical alarm rules:
[0114] 1. Level 1 Alert (Red): Area risk score ≥ 80 or ransomware detected, triggering SMS + audio-visual alarm;
[0115] 2. Level 2 Alarm (Orange): Equipment risk score ≥ 60, notification via email and work order system;
[0116] 3. Level 3 Alarm (Yellow): Personnel stay abnormally for more than 10 minutes, local pop-up notification.
[0117] In one embodiment of the present invention, the method further includes hash replacement and noise injection of sensitive information in the abnormal event to generate anonymized feature vectors, and combining the inherent risks of the device and the attack chain stage information to verify the authenticity of the abnormal event, merge duplicate events and label the risk level.
[0118] S53: Generate a standardized report based on the abnormal event and the corresponding risk level, and perform algorithm encryption processing on the standardized report to generate an anonymized early warning analysis report.
[0119] It should be noted that the generated abnormal events, after being privacy-enhanced, are injected into the attack path graph carrying key attributes (such as event type, risky device ID, and attack chain stage label). The graph updates node states and adjusts attack chain confidence accordingly. When defense strategy generation is initiated, the latest node attributes in the attack path graph are directly parsed, including the following aspects:
[0120] 1) Abnormal event type-driven defense script matching;
[0121] 2) The device ID associated with the incident risk is linked to the device's trustworthiness, which determines the defense priority;
[0122] 3) The attack chain stage tags dynamically adjust the defense response strength.
[0123] It analyzes attack path characteristics to generate defense strategy elements and dynamically adjusts defense priorities based on device trustworthiness; it verifies the effectiveness of the strategy through digital twin simulation and generates an encrypted executable instruction set, enabling intelligent generation and pre-performance verification of cross-domain defense strategies, improving the reliability and execution efficiency of the strategy, and reducing the risk of business interruption caused by misoperation.
[0124] In one embodiment of the present invention, the method further includes dynamically generating a cross-domain dynamic defense strategy based on the attack path graph and device trustworthiness, and pre-simulating the effectiveness of the defense strategy through a digital twin model, and outputting a defense instruction set, specifically including:
[0125] Analyze the node attributes in the attack path graph, construct a threat feature space, adjust the defense priority based on device trustworthiness, and generate a set of defense strategy elements (the set of defense strategy elements includes a mapping table of attack features, device status, and defense measures).
[0126] By matching attack characteristics with defense measures, an initial script is generated, and the historical defense effectiveness of each script is evaluated. The execution order of the scripts is then dynamically adjusted to generate a dynamic defense strategy.
[0127] Build digital twin models of IoT devices, inject adversarial attack traffic, conduct multi-scenario simulations of dynamic protection strategies, and evaluate the effectiveness of the defense strategies;
[0128] The defense instructions in the defense strategy are encrypted, dynamic signatures are generated by combining device fingerprints, and execution permissions are divided according to device trustworthiness to generate an encrypted set of defense instructions.
[0129] In this embodiment, device trustworthiness is used to assess the security of the IoT device itself and its potential risks in the attack chain. Device trustworthiness is the difference between dynamic trustworthiness and emergency event penalty.
[0130] The calculation process for device reliability includes the following aspects:
[0131] Step 1: Calculate the static trustworthiness of IoT devices through static security baseline assessment, including the following aspects:
[0132] 1. Firmware Integrity Verification: Verify the firmware digital signature (such as RSA-2048 or SM2 national cryptographic algorithm), verify the legality of the manufacturer's signature, compare with the baseline firmware hash library, and match known secure versions;
[0133] 2. Hardware security certification: Check whether the hardware has passed international security certifications (such as F IPS140-2, Common Criteria EAL4+) and verify the existence of a trusted execution environment;
[0134] 3. Vulnerability Repair Status: Use vulnerability scanning tools (such as Nessus, OpenVAS) to check whether the device has repaired known vulnerabilities (CVSS≥7.0). If all high-risk vulnerabilities are repaired, 100 points will be awarded; if each vulnerability is not repaired, 20 points will be deducted.
[0135] Therefore, the static credibility calculation formula can be obtained: Static credibility = 0.4 × firmware score + 0.3 × hardware score + 0.3 × vulnerability score.
[0136] Step 2: Calculate the dynamic trustworthiness of IoT devices through dynamic threat intelligence fusion, including the following aspects:
[0137] 1. Attack Chain Correlation Analysis: If a device is marked as a node in the attack chain (such as an APT attack springboard), its credibility decreases progressively with each stage of the attack.
[0138] Initial access phase: 20% decay;
[0139] Lateral movement phase: 50% attenuation;
[0140] Data leakage phase: 80% attenuation.
[0141] 2. Threat Intelligence Matching: When the device IP / firmware version matches the IoC (Indicator of Compromise) blacklist, the credibility is immediately reduced to zero.
[0142] Therefore, the formula for calculating dynamic credibility can be obtained: Dynamic credibility = Static credibility × (1 - Attenuation factor).
[0143] Step 3: Obtain the final device reliability score through comprehensive reliability calculation. The calculation formula is as follows:
[0144] Equipment trustworthiness = Dynamic trustworthiness - Emergency event penalty items;
[0145] Emergency penalty: If a zero-day vulnerability exploit is detected in the area where the device is located, the trust level will be reduced by an additional 30%.
[0146] Threshold classification can be divided into: Trustworthy (≥70), which means normal operation is allowed and only monitoring is performed; Risky (40-69), which means access to high-risk protocols is restricted; Untrustworthy (≤39), which means immediate isolation and evidence collection.
[0147] In one embodiment of the present invention, it further includes integrating early warning analysis reports and defense instruction sets to construct a three-dimensional coordinate system of devices, networks, and personnel, visually displaying the regional risk distribution, and using blockchain to mark and trace the source attack path.
[0148] It should be noted that by integrating early warning analysis reports and defense command sets, a full-cycle offensive and defensive situational view can be constructed. The early warning analysis reports provide real-time threat intelligence and risk identification, while the defense command sets contain verified response strategies and execution effect data. The integration of these two forms a closed-loop evidence chain of "attack intent - defensive action - response result," providing dynamic data input for the three-dimensional situational model and ensuring the accuracy of the visualization and the verifiability of response decisions.
[0149] By constructing a three-dimensional situational model of devices, networks, and personnel, risk data is mapped into a visual layer; blockchain technology is used to store the hash of attack operation chains, achieving tamper-proof traceability and evidence preservation, thereby providing an intuitive display of the overall security situation and accurate tracing of attack paths, enhancing the transparency and credibility of threat management in large-scale IoT environments.
[0150] In one embodiment of the present invention, an early warning analysis report and a defense instruction set are integrated to construct a three-dimensional coordinate system of devices, networks, and personnel, visually displaying the regional risk distribution, and using blockchain to mark and trace attack paths, including:
[0151] Construct a three-dimensional coordinate system that includes the device layer, network layer, and personnel layer, map location information and topology structure into coordinates, and periodically update attack chain data and associate it with the corresponding device nodes;
[0152] Based on the Kriging interpolation algorithm, discrete risk points are converted into regional risk heat maps;
[0153] A 3D engine is used to construct a visual scene, and a risk heat layer, an attack path streamline layer, and a device status marker layer are overlaid on the 3D model to display the attack path streamline and tactical tags.
[0154] A distributed log library is built based on blockchain. The input is the supply equipment and time range, and the output is the associated operation chain. The hash value is stored using blockchain.
[0155] Specifically, constructing a three-dimensional coordinate system that includes the device layer, network layer, and personnel layer includes the following aspects:
[0156] 1) Device layer: Convert the GPS coordinates of IoT devices (such as PLCs and cameras) into three-dimensional spatial points (X, Y, Z);
[0157] 2) Network Layer: Construct a communication relationship matrix between devices based on NetFlow data (network flow technology data), and generate weighted connection lines (line width = flow intensity);
[0158] 3) Personnel level: Track the real-time location of maintenance personnel through the UWB positioning system and dynamically mark it in three-dimensional space.
[0159] The system uses a 3D engine (Unity 3D Engine) to construct a visual scene with a rendering frame rate of ≥60 FPS. Risk heat layer, attack path streamline layer, and device status marker layer are overlaid on the basic 3D model. Attack path arrows (color = attack stage, red = initial access, purple = data leakage) can be drawn using Three.js (3D JavaScript library), and the MITRE ATT&CK tactical stage is marked at key nodes of the path.
[0160] By invoking the node attributes of the attack path graph, combining the execution timestamps and device fingerprint signatures of the defense instruction set, and the anonymized event feature vectors in the warning report, a cross-domain operation evidence chain is constructed. These data are used to generate unique operation hash values and stored in the blockchain. This allows the system to locate the associated device node in three-dimensional coordinates when a target device and time range are input, and to reverse-analyze the corresponding attack path, defense actions, and abnormal event characteristics, forming an immutable spatiotemporal behavior traceability system.
[0161] In summary, by leveraging the technical solutions described above in this invention, and through core technologies such as five-tuple ontology modeling, attack path graph reasoning, and multimodal situational awareness, a closed-loop link is established for device monitoring, threat analysis, strategy generation, and effect verification. In terms of monitoring, abnormal operations are captured in real time based on a device behavior fingerprint database, and early identification of attack intent is achieved by combining this with a cross-domain tactical rule base. In terms of analysis, attack chains are dynamically reasoned using graph neural networks, and threat confidence is quantified through a Bayesian model, effectively shortening the detection time of APT (Advanced Persistent Threat) attacks in industrial internet scenarios. In terms of defense, the effectiveness of strategies is verified through digital twin pre-simulation, and the immutable traceability of attack paths is achieved by combining blockchain annotation, thus forming a full-cycle protection capability of "monitoring-analysis-defense-tracing," which is particularly suitable for the high real-time security requirements of critical infrastructure such as power and water utilities.
[0162] Addressing the characteristics of highly covert and data-sensitive cross-domain attacks in the Internet of Things (IoT), this solution maps attack tactics to device-level operations using a five-tuple ontology model. Combined with graph neural network spatiotemporal inference technology, it can successfully identify novel attack chains in various IoT scenarios. Simultaneously, by injecting noise and performing hash replacement on the original traffic characteristics, data privacy requirements are met, thus balancing detection accuracy and privacy protection. Compared to traditional solutions, this effectively reduces data availability issues. By simulating the real physical environment through a digital twin model and injecting adversarial traffic to pre-demonstrate the effectiveness of defense strategies, it avoids the business interruption risks associated with traditional trial-and-error methods. Furthermore, by integrating a device-network-personnel three-dimensional coordinate system, abstract attack paths are transformed into visualized heatmaps and attack flow lines, allowing maintenance personnel to quickly locate high-risk areas and achieve visualized risk warnings and rapid tracking.
[0163] Another embodiment of the present invention provides a data security monitoring and early warning system based on the Internet of Things. For details, please refer to [link to relevant documentation]. Figure 2 , Figure 2 The diagram shown illustrates a data security monitoring and early warning system based on the Internet of Things (IoT) according to one embodiment of the present invention. It includes an acquisition module 11, a construction module 12, a parsing module 13, an identification module 14, and a generation module 15.
[0164] The acquisition module 11 is used to acquire the real-time operating characteristics of the target IoT device and construct a device behavior fingerprint database based on the real-time operating characteristics;
[0165] The construction module 12 is used to construct a five-tuple ontology model based on the device behavior fingerprint library, and to map the general tactical framework to the IoT device operation scenario according to the five-tuple ontology model, thereby generating a cross-domain tactical association rule library.
[0166] The parsing module 13 is used to parse and process the multi-source interaction data between the target IoT device and the external environment according to the cross-domain tactical association rule base, and construct an attack path map based on the parsed multi-source interaction features.
[0167] The identification module 14 is used to input the attack path map into a pre-built graph neural network model to obtain a multi-stage attack chain, identify the persistent threat attack chain in the multi-stage attack chain and calculate its confidence score.
[0168] The generation module 15 is used to perform anomaly detection on the original network traffic data corresponding to the persistent threat attack chain based on the confidence score, and generate an anonymized early warning analysis report.
[0169] Preferably, in one embodiment of the present invention, the building module is specifically used for:
[0170] Based on ontology modeling language, a five-tuple element and relationship of attacker, device, vulnerability, attack behavior and impact are defined to construct a five-tuple ontology model. The device behavior fingerprint database is used to provide device operation characteristics as a verification benchmark for the five-tuple ontology model.
[0171] Based on the aforementioned five-tuple ontology model, the tactical phases of the general tactical framework are associated with the operational scenarios of IoT devices to generate a device-level attack scenario knowledge base.
[0172] Based on natural language processing technology, attack method-affected device association pairs are extracted from the device-level attack scenario knowledge base as executable rules to generate a cross-domain tactical association rule base.
[0173] Preferably, in one embodiment of the present invention, the multi-source interactive data includes device operation logs and raw network traffic;
[0174] The parsing module is specifically used for:
[0175] The device operation logs and the raw network traffic are parsed according to protocols, and the data obtained from the protocol parsing is aligned with geographical coordinates according to a unified time base to generate a structured event stream;
[0176] Based on device type, pre-set vulnerability database and general tactical framework, the tactical phase sets the relationship between graph nodes and edges to construct an initial attack path graph that supports dynamic reasoning.
[0177] The structured event stream is mapped to the initial attack path graph, and the real-time running features are injected into the graph nodes. Spatiotemporal weights are added to the edges to generate the attack path graph.
[0178] Preferably, in one embodiment of the present invention, the identification module is specifically used for:
[0179] Based on the pre-built graph neural network model, the spatiotemporal correlation of node features and edge relationships in the attack path graph is analyzed to identify abnormal paths across devices and protocols.
[0180] Based on the abnormal path, a multi-stage attack chain conforming to the attack logic is output;
[0181] The confidence level of the multi-stage attack chain as a persistent threat attack chain is calculated using a Bayesian probability model, and then classified according to a preset confidence level rule to obtain the confidence score of the persistent threat attack chain.
[0182] Preferably, in one embodiment of the present invention, the generation module is specifically used for:
[0183] Based on the confidence score, a target anomaly detection model is selected, the original network traffic data is input into the target anomaly detection model, and a list of anomaly events is output.
[0184] Multi-factor risk weights are set, and the risk score of each abnormal event in the list of abnormal events is calculated by risk quantification. The risk level of each abnormal event is then evaluated according to a preset risk rule threshold.
[0185] Based on the abnormal events and their corresponding risk levels, a standardized report is generated. The standardized report is then encrypted using an algorithm to generate an anonymous early warning analysis report.
[0186] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of this patent should be determined by the appended claims.
Claims
1. A data security monitoring and early warning method based on the Internet of Things, characterized in that, include: Obtain the real-time operating characteristics of the target IoT device, and construct a device behavior fingerprint database based on the real-time operating characteristics; A five-tuple ontology model is constructed based on the device behavior fingerprint database, and a general tactical framework is mapped to the IoT device operation scenario according to the five-tuple ontology model to generate a cross-domain tactical association rule library. The multi-source interaction data between the target IoT device and the external environment is parsed and processed according to the cross-domain tactical association rule base, and an attack path map is constructed based on the parsed multi-source interaction features. The attack path map is input into a pre-built graph neural network model to obtain a multi-stage attack chain. The persistent threat attack chain in the multi-stage attack chain is identified and its confidence score is calculated. Based on the confidence score, anomaly detection is performed on the original network traffic data corresponding to the persistent threat attack chain, and an anonymized early warning analysis report is generated.
2. The data security monitoring and early warning method based on the Internet of Things as described in claim 1, characterized in that, The step of constructing a five-tuple ontology model based on the device behavior fingerprint database, and mapping a general tactical framework to the IoT device operation scenario according to the five-tuple ontology model, and generating a cross-domain tactical association rule library, includes: Based on ontology modeling language, a five-tuple element and relationship of attacker, device, vulnerability, attack behavior and impact are defined to construct a five-tuple ontology model. The device behavior fingerprint database is used to provide device operation characteristics as a verification benchmark for the five-tuple ontology model. Based on the aforementioned five-tuple ontology model, the tactical phases of the general tactical framework are associated with the operational scenarios of IoT devices to generate a device-level attack scenario knowledge base. Based on natural language processing technology, attack method-affected device association pairs are extracted from the device-level attack scenario knowledge base as executable rules to generate a cross-domain tactical association rule base.
3. The data security monitoring and early warning method based on the Internet of Things as described in claim 1, characterized in that, The multi-source interactive data includes device operation logs and raw network traffic; The step of parsing and processing the multi-source interaction data between the target IoT device and the external environment based on the cross-domain tactical association rule base, and constructing an attack path graph based on the parsed multi-source interaction features, includes: The device operation logs and the raw network traffic are parsed according to protocols, and the data obtained from the protocol parsing is aligned with geographical coordinates according to a unified time base to generate a structured event stream; Based on device type, pre-set vulnerability database and general tactical framework, the tactical phase sets the relationship between graph nodes and edges to construct an initial attack path graph that supports dynamic reasoning. The structured event stream is mapped to the initial attack path graph, and the real-time running features are injected into the graph nodes. Spatiotemporal weights are added to the edges to generate the attack path graph.
4. The data security monitoring and early warning method based on the Internet of Things as described in claim 1, characterized in that, The step of inputting the attack path map into a pre-constructed graph neural network model to obtain a multi-stage attack chain, identifying persistent threat attack chains within the multi-stage attack chain, and calculating their confidence scores includes: Based on the pre-built graph neural network model, the spatiotemporal correlation of node features and edge relationships in the attack path graph is analyzed to identify abnormal paths across devices and protocols. Based on the abnormal path, a multi-stage attack chain conforming to the attack logic is output; The confidence level of the multi-stage attack chain as a persistent threat attack chain is calculated using a Bayesian probability model, and then classified according to a preset confidence level rule to obtain the confidence score of the persistent threat attack chain.
5. The data security monitoring and early warning method based on the Internet of Things as described in claim 1, characterized in that, The step of performing anomaly detection on the original network traffic data corresponding to the persistent threat attack chain based on the confidence score, and generating an anonymized early warning analysis report, includes: Based on the confidence score, a target anomaly detection model is selected, the original network traffic data is input into the target anomaly detection model, and a list of anomaly events is output. Multi-factor risk weights are set, and the risk score of each abnormal event in the list of abnormal events is calculated by risk quantification. The risk level of each abnormal event is then evaluated according to a preset risk rule threshold. Based on the abnormal events and their corresponding risk levels, a standardized report is generated. The standardized report is then encrypted using an algorithm to generate an anonymous early warning analysis report.
6. A data security monitoring and early warning system based on the Internet of Things, characterized in that, include: The acquisition module is used to acquire the real-time operating characteristics of the target IoT device and construct a device behavior fingerprint database based on the real-time operating characteristics; The construction module is used to construct a five-tuple ontology model based on the device behavior fingerprint library, and to map the general tactical framework to the IoT device operation scenario according to the five-tuple ontology model, thereby generating a cross-domain tactical association rule library. The parsing module is used to parse and process the multi-source interaction data between the target IoT device and the external environment according to the cross-domain tactical association rule base, and construct an attack path map based on the parsed multi-source interaction features; The identification module is used to input the attack path map into a pre-built graph neural network model to obtain a multi-stage attack chain, identify the persistent threat attack chain in the multi-stage attack chain and calculate its confidence score. The generation module is used to perform anomaly detection on the original network traffic data corresponding to the persistent threat attack chain based on the confidence score, and generate an anonymized early warning analysis report.
7. The data security monitoring and early warning system based on the Internet of Things as described in claim 6, characterized in that, The building module is specifically used for: Based on ontology modeling language, a five-tuple element and relationship of attacker, device, vulnerability, attack behavior and impact are defined to construct a five-tuple ontology model. The device behavior fingerprint database is used to provide device operation characteristics as a verification benchmark for the five-tuple ontology model. Based on the aforementioned five-tuple ontology model, the tactical phases of the general tactical framework are associated with the operational scenarios of IoT devices to generate a device-level attack scenario knowledge base. Based on natural language processing technology, attack method-affected device association pairs are extracted from the device-level attack scenario knowledge base as executable rules to generate a cross-domain tactical association rule base.
8. The data security monitoring and early warning system based on the Internet of Things as described in claim 6, characterized in that, The multi-source interactive data includes device operation logs and raw network traffic; The parsing module is specifically used for: The device operation logs and the raw network traffic are parsed according to protocols, and the data obtained from the protocol parsing is aligned with geographical coordinates according to a unified time base to generate a structured event stream; Based on device type, pre-set vulnerability database and general tactical framework, the tactical phase sets the relationship between graph nodes and edges to construct an initial attack path graph that supports dynamic reasoning. The structured event stream is mapped to the initial attack path graph, and the real-time running features are injected into the graph nodes. Spatiotemporal weights are added to the edges to generate the attack path graph.
9. The data security monitoring and early warning system based on the Internet of Things as described in claim 6, characterized in that, The identification module is specifically used for: Based on the pre-built graph neural network model, the spatiotemporal correlation of node features and edge relationships in the attack path graph is analyzed to identify abnormal paths across devices and protocols. Based on the abnormal path, a multi-stage attack chain conforming to the attack logic is output; The confidence level of the multi-stage attack chain as a persistent threat attack chain is calculated using a Bayesian probability model, and then classified according to a preset confidence level rule to obtain the confidence score of the persistent threat attack chain.
10. The data security monitoring and early warning system based on the Internet of Things as described in claim 6, characterized in that, The generation module is specifically used for: Based on the confidence score, a target anomaly detection model is selected, the original network traffic data is input into the target anomaly detection model, and a list of anomaly events is output. Multi-factor risk weights are set, and the risk score of each abnormal event in the list of abnormal events is calculated by risk quantification. The risk level of each abnormal event is then evaluated according to a preset risk rule threshold. Based on the abnormal events and their corresponding risk levels, a standardized report is generated. The standardized report is then encrypted using an algorithm to generate an anonymous early warning analysis report.
Citation Information
Patent Citations
APT attack traceability graph analysis method
CN116366376A
Network attack link tracking and threat situation reasoning method based on knowledge graph
CN119544327A
Electric power Internet of Things safety response method and system based on risk assessment
CN119628885A
Method and system for evaluating capability maturity of industrial internet data security
CN119996078A
APT attack chain reconstruction method based on knowledge graph and graph neural network
CN120185934A
Cited By
Traffic analysis audit backtracking method and device, computer equipment and storage medium
CN121151136A
Test mirror image generation method and device, equipment, storage medium and program product
CN121567410A
Zero-day vulnerability detection method and system
CN122093197A
Zero-day vulnerability detection methods and systems
CN122093197B