Equipment safety monitoring method and system based on edge computing
By applying a multi-dimensional reputation assessment system and time-varying weight coefficients, the problem of dynamic reputation assessment of edge detection nodes is solved, improving the accuracy and responsiveness of equipment security monitoring, and realizing comprehensive trust measurement and efficient threat determination of edge detection nodes.
Patent Information
- Application Number
- CN202511181773.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-12-09
AI Technical Summary
Existing equipment security monitoring technologies lack a dynamic reputation assessment mechanism for edge detection nodes and do not consider the differences in core performance such as node detection accuracy and response timeliness. This leads to false alarms and missed alarms from low-reliability nodes interfering with the overall judgment results. Furthermore, threat judgment often uses fixed weights or simple voting methods, which cannot adapt to high-frequency threat or high false alarm scenarios.
A multi-dimensional node reputation assessment system is adopted, including detection accuracy score, response timeliness score, and behavior consistency score. The overall reputation of a node is calculated through time-varying weight coefficients, and the weights are adjusted according to the network threat situation and the node's historical performance. By combining weighted calculation and adaptive threat confirmation threshold, high-reputation nodes are dynamically selected to participate in the judgment, and the node reputation is updated to suppress the interference of low-reliability nodes.
It enables comprehensive and accurate assessment of edge detection nodes, improves the accuracy of threat determination and response sensitivity, reduces false alarms and false negatives, and ensures optimal detection performance in dynamic network environments.
Smart Images

Figure CN121098549A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security monitoring technology, specifically to a device security monitoring method and system based on edge computing. Background Technology
[0002] With the rapid development of IoT technology, a massive number of smart devices are connecting to the network, and the real-time data generated by these devices is growing exponentially. Edge computing, with its advantages of low latency and high real-time performance, has become a core technological support for device security monitoring—by performing local data processing and threat detection at edge nodes near the devices, it can effectively avoid the network bandwidth pressure and response latency problems of traditional centralized cloud monitoring. However, edge nodes are geographically dispersed, have significant differences in hardware performance, and face diverse and dynamic network attacks (such as malicious intrusion, data tampering, and injection of false commands). Ensuring the reliability of edge detection nodes and improving the accuracy of threat assessment have become key challenges for device security monitoring in edge computing environments.
[0003] Existing equipment security monitoring technologies lack a dynamic reputation assessment mechanism for edge detection nodes and fail to consider core performance differences such as node detection accuracy and response timeliness. This leads to false alarms and missed alarms from low-reliability nodes interfering with the overall judgment results. Secondly, threat judgment often uses fixed weights or simple voting methods, which cannot adjust weights based on the node's historical performance and network threat situation, resulting in insufficient adaptability in high-frequency threat or high false alarm scenarios. Thirdly, the node management mechanism is rigid and has not established a reputation-based dynamic screening mechanism, allowing low-reputation nodes to remain in the detection network for a long time, continuously lowering the overall monitoring accuracy. Summary of the Invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by this invention is: the lack of a dynamic reputation evaluation mechanism for edge detection nodes, and the failure to consider the differences in core performance such as node detection accuracy and response timeliness, which leads to false alarms and missed alarms of low-reliability nodes interfering with the overall judgment results.
[0006] To address the aforementioned technical problems, the present invention provides the following technical solution: a device security monitoring method based on edge computing, comprising the following steps:
[0007] For each edge detection node, a comprehensive node reputation score is calculated, which includes a detection accuracy score, a response timeliness score, and a behavior consistency score.
[0008] When a potential security threat is detected, the judgment results of each node involved in the detection are collected, and a weighted calculation is performed based on the overall reputation of each node to obtain the final threat judgment result.
[0009] When the final threat assessment result determines that a threat exists, a security protection command is sent to the monitored device; when the final threat assessment result is a false alarm, the overall reputation of each participating node is updated.
[0010] The final threat assessment result is compared and verified with the actual security incident. Based on the verification result, the overall reputation score of each node participating in the assessment is adjusted. Nodes with an overall reputation score below the threshold are excluded from the core detection network.
[0011] As a preferred embodiment of the device security monitoring method based on edge computing described in this invention, the calculation of the node's comprehensive reputation includes:
[0012] Detection accuracy score The calculation formula is expressed as follows:
[0013] ;
[0014] in, This represents the number of true positive tests. This represents the number of false positive tests. This represents the number of false negative tests. The time decay coefficient, For a specific moment;
[0015] Response timeliness score The calculation formula is expressed as follows:
[0016] ;
[0017] in, For threat detection response time, For time-sensitive parameters, This is the time decay coefficient;
[0018] Behavioral consistency score The calculation formula is expressed as follows:
[0019] ;
[0020] in, This is the detection result for this node. As a result of network consensus, The maximum deviation value, This is the time decay coefficient.
[0021] As a preferred embodiment of the device security monitoring method based on edge computing described in this invention, wherein: the node's comprehensive reputation... Calculated using adaptive weights:
[0022] ;
[0023] in, , , These are time-varying weighting coefficients;
[0024] The time-varying weighting coefficients are adjusted based on the network threat situation and the historical performance of nodes. When the network detects high-frequency threats, the weight of the response timeliness score is increased. When the false positive rate increases, the weight of the detection accuracy score should be increased. .
[0025] The beneficial effects of this preferred technical solution are as follows: It uses time-varying weight coefficients to calculate the comprehensive reputation of nodes, which solves the problem that fixed weights cannot adapt to dynamic network environments. By adjusting the weight coefficients according to the network threat situation (such as increasing the weight of response timeliness when there are high-frequency threats) and the historical performance of nodes (such as increasing the weight of accuracy when there is a high false alarm rate), the reputation assessment can accurately match the actual monitoring needs.
[0026] As a preferred embodiment of the device security monitoring method based on edge computing described in this invention, the method for calculating the time-varying weight coefficient includes:
[0027] ;
[0028] in, As the basic weight for the accuracy score of the detection, As a regulating factor, This represents the false alarm rate for the previous period. For the target false alarm rate, Weighting for accuracy scoring;
[0029] ;
[0030] in, As the basis for the timeliness score, As a regulating factor, As the frequency of current threats, This is a normal threat frequency;
[0031] ;
[0032] When the calculated weighting coefficients exceed the preset range Boundary constraint processing is performed at that time.
[0033] As a preferred embodiment of the device security monitoring method based on edge computing described in this invention, the step of detecting potential security threats includes:
[0034] Each edge detection node collects real-time operating parameters, network traffic data, and environmental status information of the monitored devices;
[0035] The collected data is analyzed and processed, and a potential threat report is generated when the detection results exceed the preset threat threshold.
[0036] Each edge detection node reports the potential threat to the network, triggering a multi-node collaborative judgment process.
[0037] As a preferred embodiment of the edge computing-based device security monitoring method of the present invention, the weighted calculation process includes:
[0038] Set the overall reputation of nodes Higher than the admission threshold The nodes participate in the calculation of the final threat assessment result;
[0039] The formula for calculating the final threat determination result is as follows:
[0040] ;
[0041] in, Let i be the overall reputation score of the i-th node. This represents the threat detection result for the i-th node;
[0042] When the final threat determination result Exceeding the threat confirmation threshold At that time, it was determined that a threat existed.
[0043] The beneficial effects of this preferred technical solution are as follows: it specifies the node admission mechanism for participating in threat determination and the weighted calculation method for the final result, and reduces the interference of low-reliability nodes by screening high-reputation nodes to participate in the determination.
[0044] As a preferred embodiment of the edge computing-based device security monitoring method described in this invention, the threat confirmation threshold θthreat employs an adaptive adjustment mechanism.
[0045] Calculate the average and standard deviation of the overall reputation of all nodes currently participating in the judgment;
[0046] When the average overall reputation score of nodes is higher than the preset high reputation threshold and the standard deviation is lower than the preset consistency threshold, the threat confirmation threshold is lowered. ;
[0047] When the average overall reputation score of nodes is lower than the preset low reputation threshold or the standard deviation is higher than the preset difference threshold, the threat confirmation threshold is increased. ;
[0048] Maintain the threat confirmation threshold when both the average and standard deviation of the node's overall reputation are at a moderate level. .
[0049] The beneficial effects of this preferred technical solution are as follows: the threshold can be flexibly changed according to the overall reputation level (average) and consistency (standard deviation) of the participating nodes. When the node reputation is high and the consistency is good, the threshold can be lowered to respond to threats quickly; when the node reputation is low or the divergence is large, the threshold can be raised to reduce false alarms, thus achieving a balance between threat response sensitivity and accuracy.
[0050] As a preferred embodiment of the device security monitoring method based on edge computing described in this invention, the step of updating the overall reputation of each participating node includes:
[0051] When the final threat assessment result is a false alarm, distinguish between the leading false alarm node and the following false alarm nodes. The leading false alarm node is the node that contributes the largest weight in the weighted calculation and is determined to be a threat. The leading false alarm node is severely penalized, while the following false alarm nodes are lightly penalized.
[0052] When the final threat assessment result misses a real threat, a distinction is made between the leading missed threat node and the following missed threat nodes. The leading missed threat node is the node that contributes the largest weight in the weighted calculation and is determined to have no threat. The detection accuracy score of the leading missed threat node is severely penalized, while the following missed threat nodes are lightly penalized.
[0053] As a preferred embodiment of the device security monitoring method based on edge computing described in this invention, the step of adjusting the overall reputation of each node participating in the judgment includes:
[0054] Within a preset verification time window, the timing and type of actual security events are determined by monitoring the system logs, performance index anomalies, and actual fault occurrences of the monitored devices.
[0055] The actual security events are matched and compared with the final threat assessment results at the corresponding time points, and the actual detection accuracy of each participating node is statistically analyzed.
[0056] The detection accuracy score of each node is recalculated based on the actual detection accuracy. Nodes with an accuracy higher than the expected value receive an increase in reputation, while nodes with an accuracy lower than the expected value receive a decrease in reputation.
[0057] When a node’s overall reputation score is below the exclusion threshold for multiple consecutive verification periods, the node will be removed from the core detection network.
[0058] This invention provides a device security monitoring system based on edge computing.
[0059] To address the aforementioned technical problems, the present invention provides the following technical solution: a device security monitoring system based on edge computing, comprising a node reputation management module, a threat determination module, a node screening module, and a verification and comparison module;
[0060] The node reputation management module is used to calculate the overall reputation of each edge detection node.
[0061] When the threat determination module detects a potential security threat, it is responsible for collecting the judgment results of each node participating in the detection, and performing a weighted calculation based on the overall reputation of each node as a weight to obtain the final threat determination result.
[0062] The node filtering module dynamically filters edge detection nodes based on the comprehensive reputation score of the nodes output by the node reputation management module.
[0063] The verification and comparison module is responsible for comparing and verifying the final threat assessment result with the actual security incident.
[0064] The beneficial effects of this invention are:
[0065] By establishing a multi-dimensional node comprehensive reputation evaluation system, which organically integrates detection accuracy scoring, response timeliness scoring, and behavior consistency scoring, a comprehensive and accurate credibility quantification mechanism for edge detection nodes is formed. This multi-dimensional reputation evaluation not only overcomes the shortcomings of the single-dimensional node performance evaluation in existing technologies, but more importantly, through the synergistic effect of the three dimensions, it can identify abnormal node behavior patterns that cannot be detected by a single indicator, thus achieving a three-dimensional evaluation of edge detection nodes.
[0066] A time-varying weighting coefficient is used to calculate the overall reputation score of nodes, enabling the reputation assessment to adaptively adjust based on the network threat landscape and the node's historical performance. When the network detects a high-frequency threat, the weight of the response timeliness score is automatically increased; when the network false alarm rate rises, the weight of the detection accuracy score is increased. This weighting adjustment mechanism, combined with static node reputation assessment, ensures that the entire monitoring method maintains optimal detection performance configuration under different threat environments, compared to traditional fixed-weight schemes.
[0067] The final threat assessment result is derived by weighting the overall reputation of nodes, which changes the traditional simple voting or fixed-weight assessment method. The detection results of high-reputation nodes are given greater weight, and the interference of low-reputation nodes is effectively suppressed. This reputation-driven decision-making mechanism, combined with multi-node collaborative detection, achieves a perfect balance between collective wisdom and individual credibility, thus improving the accuracy of threat assessment. Attached Figure Description
[0068] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0069] Figure 1 This is a general flowchart of a device security monitoring method based on edge computing, provided as an embodiment of the present invention. Detailed Implementation
[0070] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0071] Example 1, referring to Figure 1 This is one embodiment of the present invention, which provides a device security monitoring method based on edge computing, including the following steps:
[0072] S1. Calculate the overall reputation score for each edge detection node. The overall reputation score includes the detection accuracy score, the response timeliness score, and the behavior consistency score.
[0073] In this embodiment, edge device security monitoring includes 5 edge detection nodes, namely nodes A, B, C, D and E, and it is necessary to calculate the overall reputation score of each node.
[0074] The calculation of a node's overall reputation includes:
[0075] Detection accuracy score The calculation formula is expressed as follows:
[0076] ;
[0077] in, This represents the number of true positive tests. This represents the number of false positive tests. This represents the number of false negative tests. The time decay coefficient, For a specific moment;
[0078] Response timeliness score The calculation formula is expressed as follows:
[0079] ;
[0080] in, For threat detection response time, For time-sensitive parameters, This is the time decay coefficient;
[0081] Behavioral consistency score The calculation formula is expressed as follows:
[0082] ;
[0083] in, This is the detection result for this node. As a result of network consensus, The maximum deviation value, This is the time decay coefficient.
[0084] Node overall reputation Calculated using adaptive weights:
[0085] ;
[0086] in, , , These are time-varying weighting coefficients;
[0087] The time-varying weighting coefficients are adjusted based on the network threat landscape and the historical performance of nodes. When the network detects high-frequency threats, the weight of the response timeliness score is increased. When the false positive rate increases, the weight of the detection accuracy score should be increased. .
[0088] The calculation methods for time-varying weighting coefficients include:
[0089] ;
[0090] in, As the basic weight for the accuracy score of the detection, As a regulating factor, This represents the false alarm rate for the previous period. For the target false alarm rate, Weighting for accuracy scoring;
[0091] ;
[0092] in, As the basis for the timeliness score, As a regulating factor, As the frequency of current threats, This is a normal threat frequency;
[0093] ;
[0094] When the calculated weighting coefficients exceed the preset range Boundary constraint processing is performed at that time.
[0095] In this implementation, taking node A as an example, its performance in the past 100 threat detections is statistically analyzed: number of true positive detections TP=85 (correctly identified 85 real threats), number of false positive detections FP=8 (falsely reported 8 non-existent threats), and number of false negative detections FN=7 (missed 7 real threats).
[0096] Set time decay coefficient The detection accuracy score at the current time t is calculated according to the formula. Assume that node A's detection accuracy score at the previous time was... The detection accuracy score at the current moment is:
[0097] .
[0098] In the calculation of response timeliness score, the average response time of node A after detecting a threat. Set time sensitivity parameters Time decay coefficient Assuming the response timeliness score in the previous moment. The timeliness score for the response at the current moment is:
[0099] .
[0100] In the behavioral consistency score calculation process, in the most recent threat detection, the detection result of node A is... (representing a 75% threat probability), while the consensus result formed by other nodes in the network. Set the maximum deviation value Time decay coefficient Assuming the behavioral consistency score from the previous moment... The behavioral consistency score at the current moment is:
[0101] .
[0102] Subsequently, it was detected that the frequency of threats in the current network environment was high, and the false alarm rate in the previous period was high. Target false alarm rate Current frequency of threat occurrence Normal threat frequency .
[0103] Set base weights Regulatory factors ; Regulatory factors ,but:
[0104] ;
[0105] .
[0106] because Exceeded the preset range Boundary constraint processing is performed to... Adjusted to 0.7.
[0107] Accordingly, Similarly, boundary constraints are applied and adjusted to 0.1.
[0108] After reallocation: , , .
[0109] Ultimately, node A's overall reputation score is:
[0110] ;
[0111] The same calculation method was applied to other nodes, resulting in a comprehensive reputation score of 0.689 for node B, 0.845 for node C, 0.432 for node D, and 0.591 for node E. This multi-dimensional reputation assessment mechanism accurately quantifies the comprehensive credibility of each edge detection node.
[0112] S2. When a potential security threat is detected, the judgment results of each node involved in the detection are collected, and a weighted calculation is performed based on the overall reputation of each node to obtain the final threat judgment result.
[0113] In this embodiment, the complete process of threat detection and determination is demonstrated based on the overall reputation scores of each node calculated in step S1 (Node A: 0.777, Node B: 0.689, Node C: 0.845, Node D: 0.432, Node E: 0.591).
[0114] It's important to know that the steps for detecting potential security threats include A1 through A3:
[0115] A1. Each edge detection node collects the operating parameters, network traffic data, and environmental status information of the monitored devices in real time;
[0116] Each edge detection node simultaneously collects data from the monitored industrial controller. Node A collected data showing a CPU utilization of 89% and a memory utilization of 76%; Node B detected abnormal network traffic, with inbound traffic surging to 3.2 times the normal level; Node C monitored that the equipment temperature rose to 68°C, exceeding the normal operating temperature range; Node D collected data showing that the ambient electromagnetic radiation intensity was 1.8 times the normal value; Node E detected abnormal fluctuations in the equipment vibration frequency.
[0117] A2. Analyze and process the collected data, and generate a potential threat report when the detection results exceed the preset threat threshold;
[0118] Each node runs a local threat detection algorithm for analysis. Node A determines the threat probability to be 0.75 based on resource utilization; Node B determines the threat probability to be 0.82 based on abnormal network traffic patterns; Node C determines the threat probability to be 0.68 based on abnormal temperature; Node D determines the threat probability to be 0.45 based on electromagnetic radiation analysis; and Node E determines the threat probability to be 0.39 based on vibration patterns. With a threat threshold set to 0.6, nodes A, B, and C generate potential threat reports.
[0119] A3. Each edge detection node reports potential threats to the network, triggering a multi-node collaborative judgment process.
[0120] Nodes A, B, and C report their respective potential threats to the network, while nodes D and E also report their detection results (below the threshold but still of reference value). After collecting the judgment results from all nodes, a multi-node collaborative judgment process is triggered.
[0121] It is important to know that the specific implementation of the multi-node collaborative decision-making process includes:
[0122] By establishing a collaborative decision buffer, the detection results of all nodes within the same time window (5 seconds) are collected. Each node encapsulates its threat probability value, detection timestamp, and node identifier into a data packet and reports it.
[0123] Then, check the timestamps of the data packets from each node to ensure that the time difference does not exceed 1 second, thus guaranteeing the timeliness of the data. At the same time, verify the validity of the node identifiers to exclude abnormal or forged data packets.
[0124] Once all data packets from participating nodes are collected, the overall reputation score of each node is read as a weight parameter, and a reputation-based threat assessment algorithm is initiated.
[0125] After the collaborative assessment is completed, the final threat assessment result will be distributed to all participating nodes.
[0126] The weighted calculation process includes B1~B2:
[0127] B1. Set the overall reputation of nodes Higher than the admission threshold The nodes participate in the calculation of the final threat assessment result;
[0128] The formula for calculating the final threat assessment result is as follows:
[0129] ;
[0130] in, Let i be the overall reputation score of the i-th node. This represents the threat detection result for the i-th node;
[0131] In this application embodiment, an admission threshold is set. The overall reputation of each node is used for screening:
[0132] Node A (0.777) > 0.65, which meets the condition;
[0133] Node B (0.689) > 0.65, which meets the condition;
[0134] Node C (0.845) > 0.65, which meets the condition;
[0135] Node D (0.432) < 0.65, does not meet the condition, so it is excluded;
[0136] Node E (0.591) < 0.65, does not meet the condition, so it is excluded.
[0137] Therefore, only nodes A, B, and C participate in the calculation of the final threat determination result.
[0138] The final threat assessment result is obtained by using a formula: .
[0139] B2. When the final threat assessment result is... Exceeding the threat confirmation threshold At that time, it was determined that a threat existed.
[0140] The threat confirmation threshold θthreat employs an adaptive adjustment mechanism, including B2.1~B2.4:
[0141] B2.1 Calculate the average and standard deviation of the overall reputation of all nodes currently participating in the judgment;
[0142] The average overall reputation of the three nodes involved in the judgment:
[0143] ;
[0144] Standard deviation calculation:
[0145] .
[0146] B2.2 When the average overall reputation score of nodes is higher than the preset high reputation threshold and the standard deviation is lower than the preset consistency threshold, the threat confirmation threshold is lowered. ;
[0147] B2.3 When the average overall reputation score of a node is lower than the preset low reputation threshold or the standard deviation is higher than the preset difference threshold, the threat confirmation threshold is increased. ;
[0148] B2.4 When the average and standard deviation of the node's overall reputation are both at a moderate level, maintain the threat confirmation threshold. .
[0149] The high reputation threshold is set to 0.75, and the consistency threshold is set to 0.08. The current average value (0.770) > 0.75 and the standard deviation (0.064) < 0.08, meeting the conditions for lowering the threat confirmation threshold. The original threat confirmation threshold (θthreat) was set to 0.70. Based on the current network nodes' high reputation and good consistency, the threat confirmation threshold is lowered to 0.65.
[0150] Final Threat Assessment Results Therefore, the system determined that a threat existed.
[0151] S3. When the final threat assessment result determines that a threat exists, send a security protection command to the monitored device; when the final threat assessment result is a false alarm, update the overall reputation of each participating node.
[0152] Based on the final threat assessment result F=0.746 (a threat is determined to exist) obtained in step S2, this embodiment demonstrates the threat response execution and subsequent reputation update process. Upon confirming the existence of a security threat, a security protection instruction packet is immediately sent to the monitored industrial controller. This includes actions such as reducing the CPU operating frequency to 50% to decrease system load; initiating network access control to block connection requests from abnormal IP addresses; and activating the equipment cooling system to reduce the operating temperature to a safe range.
[0153] The steps for updating the overall reputation of each participating node include C1~C2:
[0154] C1. When the final threat assessment result is a false alarm, distinguish between the leading false alarm node and the following false alarm nodes. The leading false alarm node is the node that contributes the largest weight in the weighted calculation and is determined to be a threat. Apply a heavy penalty to the leading false alarm node and a light penalty to the following false alarm nodes.
[0155] In one implementation, assuming that after 30 minutes of monitoring and verification, it is found that the monitored device is actually operating normally and no real security threat has occurred, the system determines that this is a false alarm event.
[0156] During the weighted calculation process, the weight contribution of each participating node is as follows:
[0157] The weight contribution of node A = 0.777 × 0.75 = 0.583;
[0158] The weight contribution of node B = 0.689 × 0.82 = 0.565;
[0159] The weight contribution of node C = 0.845 × 0.68 = 0.575.
[0160] Node A has the largest weight contribution (0.583) and is judged to pose a threat (Di=0.75>0.6), therefore it is identified as the leading false alarm node. Nodes B and C are follower false alarm nodes.
[0161] Node A, the primary false alarm leader, is severely penalized for its detection accuracy score. ;
[0162] Follow false alarm node B: apply a slight penalty to the detection accuracy score. ;
[0163] Follow the false positive node C: apply a slight penalty to the detection accuracy score. .
[0164] Then recalculate the overall reputation of each node.
[0165] C2. When the final threat assessment result misses a real threat, distinguish between the leading missed threat node and the following missed threat nodes. The leading missed threat node is the node that contributes the largest weight in the weighted calculation and is determined to have no threat. The detection accuracy score of the leading missed threat node is severely penalized, while the following missed threat nodes are lightly penalized.
[0166] Suppose that in another detection, the final threat assessment result is F=0.45 (indicating no threat), but actual monitoring reveals that the device has indeed suffered a cyberattack, and the system determines it as a missed event.
[0167] The threat detection results for each node in this test are as follows:
[0168] Node A: Di=0.35 (no threat detected);
[0169] Node B: Di=0.42 (no threat detected);
[0170] Node C: Di=0.58 (no threat is detected).
[0171] Therefore, the weight contribution of each participating node is:
[0172] The weight contribution of node A = 0.777 × 0.35 = 0.272;
[0173] The weight contribution of node B = 0.689 × 0.42 = 0.289;
[0174] The weight contribution of node C = 0.845 × 0.58 = 0.490.
[0175] Node C has the largest weight contribution (0.490) and is determined to pose no threat (Di=0.58<0.6), therefore it is identified as the dominant missed detection node. Nodes A and B are follower missed detection nodes.
[0176] The dominant false negative node C is severely penalized based on its detection accuracy score. ;
[0177] Follow the missed detection node A: apply a slight penalty to the detection accuracy score. ;
[0178] Follow the missed detection node B: apply a slight penalty to the detection accuracy score. .
[0179] The numerical values for severe and mild penalties are based on the degree of responsibility of each node in the error judgment. Leading nodes bear primary responsibility and are therefore punished more severely, while follower nodes bear secondary responsibility and are therefore punished relatively less severely. This differentiated approach avoids a simplistic "one-size-fits-all" punishment method.
[0180] S4. Compare and verify the final threat assessment results with the actual security incidents. Adjust the overall reputation of each node participating in the assessment based on the verification results. Nodes with an overall reputation below the threshold are excluded from the core detection network.
[0181] The steps for adjusting the overall reputation of each node involved in the judgment include D1~D4:
[0182] D1. Within the preset verification time window, determine the occurrence time and type of real security events by monitoring the system logs, abnormal performance indicators, and actual fault occurrences of the monitored devices.
[0183] D2. Match and compare real security events with the final threat assessment results at the corresponding time points, and calculate the actual detection accuracy of each participating node;
[0184] D3. Recalculate the detection accuracy score of each node based on the actual detection accuracy. Nodes with an accuracy higher than the expected value will have their reputation improved, while nodes with an accuracy lower than the expected value will have their reputation reduced.
[0185] D4. When a node’s overall reputation score is lower than the exclusion threshold for multiple consecutive verification periods, the node will be removed from the core detection network.
[0186] In this implementation, analysis of the system logs of the monitored industrial controller revealed an unauthorized access attempt recorded at 14:32:15. Simultaneously, device performance monitoring showed that CPU usage abnormally spiked to 95% at 14:35:20, and the device's main control module automatically restarted at 14:40:30. Based on this information, the system determined that a genuine network intrusion security incident occurred between 14:32 and 14:43.
[0187] The actual event was compared with the final threat assessment results at the corresponding time points. The search revealed that at 14:33:45, the detection results for each node were as follows: Node A threat probability 0.78, Node B threat probability 0.85, Node C threat probability 0.72, and the system's final threat assessment result F=0.79, correctly identifying a threat. Based on 30 days of historical data, Node A participated in 120 assessments, correctly identifying 94, with an actual detection accuracy of 78.3%; Node B participated in 115 assessments, correctly identifying 89, with an accuracy of 77.4%; and Node C participated in 118 assessments, correctly identifying 102, with an accuracy of 86.4%.
[0188] Based on the comparison between the actual detection accuracy and the expected accuracy of 80%, the reputation scores of each node were adjusted. Nodes A and B had accuracy rates lower than expected, so their detection accuracy scores were lowered to 0.795 and 0.653 respectively, and their overall reputation scores were adjusted accordingly to 0.763 and 0.663. Node C had an accuracy rate higher than expected, so its detection accuracy score increased to 0.926, and its overall reputation score increased to 0.904. Meanwhile, it was found that node D's overall reputation score was below the exclusion threshold of 0.55 for four consecutive verification periods. Therefore, it was removed from the core detection network and downgraded to an observation node, only used for data collection and not involved in threat assessment.
[0189] Example 2 is an embodiment of the present invention, which provides a device security monitoring method based on edge computing based on the previous embodiment, including a node reputation management module, a threat determination module, a node screening module, and a verification comparison module;
[0190] The node reputation management module is used to calculate the overall reputation score of each edge detection node;
[0191] When the threat assessment module detects a potential security threat, it is responsible for collecting the assessment results of each node involved in the detection, and performing a weighted calculation based on the overall reputation of each node to obtain the final threat assessment result.
[0192] The node filtering module dynamically filters edge detection nodes based on the overall node reputation score output by the node reputation management module.
[0193] The verification and comparison module is responsible for comparing and verifying the final threat assessment results with the actual security incidents.
[0194] Example 3 is an embodiment of the present invention, which provides a device security monitoring system based on edge computing, including...
[0195] This embodiment also provides an electronic device applicable to a device security monitoring method based on edge computing, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the device security monitoring method based on edge computing as proposed in the above embodiment.
[0196] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements a device security monitoring method based on edge computing as proposed in the above embodiments.
[0197] The storage medium proposed in this embodiment and the method for implementing a device security monitoring method based on edge computing proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0198] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0199] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A device security monitoring method based on edge computing, characterized in that, Includes the following steps: For each edge detection node, a comprehensive node reputation score is calculated, which includes a detection accuracy score, a response timeliness score, and a behavior consistency score. When a potential security threat is detected, the judgment results of each node involved in the detection are collected, and a weighted calculation is performed based on the overall reputation of each node to obtain the final threat judgment result. When the final threat assessment result determines that a threat exists, a security protection command is sent to the monitored device. When the final threat assessment result is a false alarm, update the overall reputation of each participating node; The final threat assessment result is compared and verified with the actual security incident. Based on the verification result, the overall reputation score of each node participating in the assessment is adjusted. Nodes with an overall reputation score below the threshold are excluded from the core detection network.
2. The device security monitoring method based on edge computing as described in claim 1, characterized in that, The calculation of the node's overall reputation includes: Detection accuracy score The calculation formula is expressed as follows: ; in, This represents the number of true positive tests. This represents the number of false positive tests. This represents the number of false negative tests. The time decay coefficient, For a specific moment; Response timeliness score The calculation formula is expressed as follows: ; in, For threat detection response time, For time-sensitive parameters, This is the time decay coefficient; Behavioral consistency score The calculation formula is expressed as follows: ; in, This is the detection result for this node. As a result of network consensus, The maximum deviation value, This is the time decay coefficient.
3. The device security monitoring method based on edge computing as described in claim 2, characterized in that, The node's overall reputation Calculated using adaptive weights: ; in, , , These are time-varying weighting coefficients; The time-varying weighting coefficients are adjusted based on the network threat situation and the historical performance of nodes. When the network detects high-frequency threats, the weight of the response timeliness score is increased. When the false positive rate increases, the weight of the detection accuracy score should be increased. .
4. The device security monitoring method based on edge computing as described in claim 3, characterized in that, The calculation method for the time-varying weighting coefficients includes: ; in, As the basic weight for the accuracy score of the detection, As a regulating factor, This represents the false alarm rate for the previous period. For the target false alarm rate, Weighting for accuracy scoring; ; in, As the basis for the timeliness score, As a regulating factor, As the frequency of current threats, This is a normal threat frequency; ; When the calculated weighting coefficients exceed the preset range Boundary constraint processing is performed at that time.
5. The device security monitoring method based on edge computing as described in claim 4, characterized in that, The steps for detecting potential security threats include: Each edge detection node collects real-time operating parameters, network traffic data, and environmental status information of the monitored devices; The collected data is analyzed and processed, and a potential threat report is generated when the detection results exceed the preset threat threshold. Each edge detection node reports the potential threat to the network, triggering a multi-node collaborative judgment process.
6. The device security monitoring method based on edge computing as described in claim 5, characterized in that, The weighted calculation process includes: Set the overall reputation of nodes Higher than the admission threshold The nodes participate in the calculation of the final threat assessment result; The formula for calculating the final threat determination result is as follows: ; in, Let i be the overall reputation score of the i-th node. This represents the threat detection result for the i-th node; When the final threat determination result Exceeding the threat confirmation threshold At that time, it was determined that a threat existed.
7. The device security monitoring method based on edge computing as described in claim 6, characterized in that, The threat confirmation threshold θthreat employs an adaptive adjustment mechanism: Calculate the average and standard deviation of the overall reputation of all nodes currently participating in the judgment; When the average overall reputation score of nodes is higher than the preset high reputation threshold and the standard deviation is lower than the preset consistency threshold, the threat confirmation threshold is lowered. ; When the average overall reputation score of nodes is lower than the preset low reputation threshold or the standard deviation is higher than the preset difference threshold, the threat confirmation threshold is increased. ; Maintain the threat confirmation threshold when both the average and standard deviation of the node's overall reputation are at a moderate level. .
8. The device security monitoring method based on edge computing as described in claim 7, characterized in that, The steps for updating the overall node reputation of each participating node include: When the final threat assessment result is a false alarm, distinguish between the leading false alarm node and the following false alarm nodes. The leading false alarm node is the node that contributes the largest weight in the weighted calculation and is determined to be a threat. The leading false alarm node is severely penalized, while the following false alarm nodes are lightly penalized. When the final threat assessment result misses a real threat, a distinction is made between the leading missed threat node and the following missed threat nodes. The leading missed threat node is the node that contributes the largest weight in the weighted calculation and is determined to have no threat. The detection accuracy score of the leading missed threat node is severely penalized, while the following missed threat nodes are lightly penalized.
9. The device security monitoring method based on edge computing as described in claim 8, characterized in that, The steps for adjusting the overall reputation of each node involved in the judgment include: Within a preset verification time window, the timing and type of actual security events are determined by monitoring the system logs, performance index anomalies, and actual fault occurrences of the monitored devices. The actual security events are matched and compared with the final threat assessment results at the corresponding time points, and the actual detection accuracy of each participating node is statistically analyzed. The detection accuracy score of each node is recalculated based on the actual detection accuracy. Nodes with an accuracy higher than the expected value receive an increase in reputation, while nodes with an accuracy lower than the expected value receive a decrease in reputation. When a node’s overall reputation score is below the exclusion threshold for multiple consecutive verification periods, the node will be removed from the core detection network.
10. A device security monitoring system based on edge computing, employing the device security monitoring method based on edge computing as described in any one of claims 1 to 9, characterized in that, It includes a node reputation management module, a threat assessment module, a node screening module, and a verification and comparison module; The node reputation management module is used to calculate the overall reputation of each edge detection node. When the threat determination module detects a potential security threat, it is responsible for collecting the judgment results of each node participating in the detection, and performing a weighted calculation based on the overall reputation of each node as a weight to obtain the final threat determination result. The node filtering module dynamically filters edge detection nodes based on the comprehensive reputation score of the nodes output by the node reputation management module. The verification and comparison module is responsible for comparing and verifying the final threat assessment result with the actual security incident.
Citation Information
Patent Citations
Threat alarm display method based on visualization
CN108111342A
Security system verification method in edge computing power secure channel
CN119788332A
Thermal power network security consensus verification method and system based on artificial intelligence
CN120110711A
Dynamic reputation evaluation and PBFT hierarchical consensus optimization system and method oriented to Internet of Vehicles
CN120455969A
Blockchain-based Intrusion Detection System for Railway Signals
US20240283801A1