A method and system for security risk assessment and early warning of IoT nodes based on big data

By developing a big data-driven method and system for assessing and warning security risks of IoT nodes, this paper addresses the problem of insufficient link stability analysis in existing technologies, enables precise risk assessment and intervention for IoT nodes, and improves the safe operation capability of industrial IoT systems.

CN121217436BActive Publication Date: 2026-04-03BEIJING HI TECH TECH
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-14
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies lack linkage analysis of network link stability after risk intervention in IoT node security risk assessment, resulting in link blind spots and making it impossible to accurately determine whether the link meets the requirements for continuous node operation after intervention, thus affecting the safe operation of industrial IoT systems.

Method used

By using a big data-based IoT node security risk assessment and early warning method and system, data collection and risk assessment are carried out at preset intervals, risk intervention and adjustment are implemented and their effectiveness is verified, and combined with node network link stability analysis, it is determined whether secondary adjustment is required, and a visual report is generated to reflect the assessment process and effect.

Benefits of technology

It enables precise risk assessment and intervention for IoT nodes, ensures link stability, enhances the safe operation capability of industrial IoT systems, and provides a comprehensive risk assessment and management closed loop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121217436B_ABST
    Figure CN121217436B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for security risk assessment and early warning of IoT nodes based on big data, belonging to the field of risk assessment and management technology. The method collects operational data from nodes such as sensors, controllers, and gateways to reflect the real-time status of the nodes, and simultaneously performs security risk assessment to determine the early warning execution process. If the early warning process involves risk intervention and adjustment, intervention is implemented based on the assessment results, and adjustment signals are generated, and the effectiveness of the intervention is verified. After verification, the stability of the node network link is analyzed to determine whether secondary adjustment is needed. After secondary adjustment, it is necessary to confirm whether a command to maintain connection stability should be sent. If no secondary adjustment is needed, a report is directly generated. This achieves closed-loop management of node security risk assessment, intervention and adjustment, and link stability analysis, thereby effectively solving the problem of low reliability of IoT node security risk assessment in existing industrial IoT systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of risk assessment and management technology, and in particular to a method and system for assessing and warning of security risks of Internet of Things (IoT) nodes based on big data. Background Technology

[0002] With the booming development of the Industrial Internet of Things (IIoT), ensuring its safe operation is crucial. Existing technologies have made progress in assessing and warning of security risks of IoT nodes. On the one hand, some solutions utilize traditional machine learning algorithms, such as support vector machines and random forests, to analyze collected operational data from IoT nodes, such as network traffic and device status parameters. By constructing classification models, normal data is distinguished from abnormal data, thereby identifying whether a node poses a security risk. For example, based on characteristics such as the node's network access frequency and data transmission volume, it can be determined whether it has been subjected to a cyberattack.

[0003] On the other hand, some systems utilize rule engine technology to pre-set a series of security-related rules. For example, when a node's IP address changes abnormally within a short period of time, or when port access exceeds a predetermined range, an early warning mechanism is triggered. Simultaneously, combined with data mining technology, patterns and regularities of normal node operation are extracted from a large amount of historical data. Once the current data deviates from this pattern, a risk assessment process is initiated, enabling the assessment and early warning of security risks to IoT nodes, thus providing a certain level of assurance for the safe operation of the industrial IoT.

[0004] For example, Chinese invention patent CN118966796B discloses a method and system for mine safety risk assessment based on intelligent Internet of Things (IoT) devices, which includes: acquiring work event data from intelligent IoT devices, identifying and extracting key features related to safety symptoms; establishing a mapping model between work events and safety symptoms, performing statistical analysis on real-time monitoring data, and identifying potential safety risk points; comparing the risk points with mine safety management regulations, generating a safety risk assessment report, and issuing early warning information based on the assessment report.

[0005] For example, the power Internet of Things (IoT) security risk assessment method, system, device, and storage medium disclosed in Chinese Invention Patent Publication No. CN115034644A includes: establishing an information network diagram, a power network diagram, and inter-network dependencies of the power IoT based on interdependent network theory; acquiring the attacked nodes in the information network diagram and assigning their state values ​​to preset attack success probabilities; then updating the state values ​​of each node in the information network diagram according to the information side-map calculation method; determining the attack success probability of each node in the power network diagram based on the updated state values ​​of each node in the information network diagram through inter-network dependencies; determining the state values ​​of each node in the power network diagram based on the attack success probabilities of each node in the power network diagram through the physical side-map calculation method; and obtaining the power IoT security risk assessment value based on the state values ​​of each node in the power network diagram.

[0006] In existing technologies, the assessment of security risks of IoT nodes focuses on the analysis of the node's own operational data (such as network traffic and device status), lacking the linkage analysis of network link stability after risk intervention. This easily leads to link blind spots, making it impossible to accurately determine whether the link meets the node's continuous operation requirements after intervention. It is also difficult to fully reflect the correlation between node security status and network transmission reliability, ultimately affecting the overall guarantee capability of the industrial IoT system's secure operation. Summary of the Invention

[0007] To address the technical problems in existing technologies, embodiments of the present invention provide a method and system for assessing and warning security risks of IoT nodes based on big data. The technical solution is as follows:

[0008] On the one hand, a big data-based method for IoT node security risk assessment and early warning is provided. This method includes: Step 1, collecting data from IoT nodes at a preset collection period to obtain node operation data reflecting the real-time operating status of IoT nodes within the preset collection period, and simultaneously conducting node security risk assessment to determine the early warning execution process of IoT nodes; Step 2, when the early warning execution process of a node is determined to be risk intervention and adjustment, risk intervention and adjustment are performed based on the security risk assessment results of each IoT node, generating risk intervention and adjustment signals, and verifying the effectiveness of intervention and adjustment to ensure that risk intervention measures effectively reduce node security risks; Step 3, when the intervention and adjustment are verified to be effective, node network link stability analysis is performed to determine whether secondary adjustment is needed to improve network link stability. If so, after secondary adjustment, it is determined whether to send instructions to maintain the stability of node network connections; otherwise, an IoT node risk assessment report is directly generated to visualize the IoT node security risk assessment process and intervention effect.

[0009] On the other hand, a big data-based IoT node security risk assessment and early warning system is provided. This system applies methods such as big data-based IoT node security risk assessment and early warning. The system includes: a node security risk assessment and early warning execution process determination module, a risk intervention and effectiveness verification module, and a node network link stability analysis and secondary adjustment judgment module. Specifically, the node security risk assessment and early warning execution process determination module collects data from IoT nodes at a preset collection period to obtain node operation data reflecting the real-time operating status of IoT nodes within the preset collection period, while simultaneously performing node security risk assessment to determine the early warning execution process for IoT nodes; the risk intervention and effectiveness verification module... The first module is used to perform risk intervention and adjustment based on the security risk assessment results of each IoT node when the early warning execution process of the node determines that it is a risk intervention and adjustment. It generates a risk intervention and adjustment signal and verifies the effectiveness of the intervention and adjustment to ensure that the risk intervention measures effectively reduce the security risks of the node. The second module is used to perform node network link stability analysis and secondary adjustment judgment when the intervention and adjustment are verified to be effective. It determines whether to perform secondary adjustment to improve the stability of the network link. If so, it determines whether to send an instruction to maintain the stability of the node network connection after the secondary adjustment. Otherwise, it directly generates an IoT node risk assessment report to visualize the IoT node security risk assessment process and intervention effect.

[0010] The beneficial effects of the technical solutions provided by the embodiments of the present invention include at least the following:

[0011] 1. This invention collects operational data from nodes such as sensors, controllers, and gateways in the Industrial Internet of Things (IIoT) at preset intervals to reflect their real-time status. Simultaneously, it conducts safety risk assessments to determine early warning execution procedures. If the early warning procedure involves risk intervention and adjustment, intervention is implemented based on the assessment results, generating adjustment signals and verifying the effectiveness of the intervention to ensure precise risk mitigation. After verification, the stability of the node network links is further analyzed to determine if secondary adjustment is needed. After secondary adjustment, it is confirmed whether to send a command to maintain connection stability. If not, a visual report is generated to present the assessment, intervention process, and effects. This process, through the linkage of node assessment, intervention verification, and link analysis, effectively solves the problem of existing technologies that only focus on node data and lack consideration for post-intervention link linkage analysis. It accurately determines whether the post-intervention link is suitable for the node's operational needs, clearly presents the correlation between node security and transmission reliability, and effectively improves the overall security assurance capability of the IIoT system.

[0012] 2. This invention retrieves a preset reference node operating data volume from the database to determine whether the acquired node operating data volume meets the evaluation criteria: if the data volume is within the reference range, it is classified as a non-essential security risk assessment, indicating smooth node data interaction and low potential risk; if the data volume is lower than the historical minimum value of the reference range, it is classified as a first essential security risk assessment, possibly due to hardware failure, network interruption, or other reasons causing data acquisition and transmission interruptions; if the data volume is higher than the historical maximum value of the reference range, it is classified as a second essential security risk assessment with higher priority, possibly due to external attacks, software anomalies, or other reasons causing a surge in data. If it is a second essential assessment, a security risk score is calculated based on the abnormal data volume reduction target, and the risk is classified as controllable / uncontrollable. The assessment results can also visualize the node security status. This process, through multi-dimensional data volume judgment and hierarchical assessment, clarifies risk priorities, solves the problem of incomplete assessment based on a single data dimension, and the quantitative scoring and visualization make the risks more intuitive, effectively improving the accuracy and efficiency of node security risk assessment.

[0013] 3. When generating risk intervention and adjustment signals, this invention first retrieves the risk intervention parameter configuration table from the database using necessary safety risk assessment identifiers and safety risk score values ​​as indexes. Next, it retrieves the node risk trend tracking status field from the table: if it is an "activated" identifier, the peak score of the real-time score sequence is used to match the intervention parameters to avoid insufficient intervention due to a temporary drop in the current score; if it is an "inactive" identifier, the current score is used to match the parameters. Finally, a signal is generated based on the matched parameters, sent to the node management terminal, and a traceability file is created, simultaneously triggering the adjustment completion signal generation mechanism. This process ensures intervention accuracy by matching differentiated parameters across score segments; it avoids insufficient intervention by combining peak scores or current scores with appropriate parameters; and it also creates a traceability file for easy tracking, effectively improving the targeting and reliability of risk intervention and laying the foundation for subsequent intervention effect verification.

[0014] 4. In verifying the effectiveness of intervention and regulation, this invention first re-collects data and calculates a re-evaluation score after detecting the regulation completion signal, according to the scoring logic. If the score decreases by a certain percentage compared to the baseline score, it is preliminarily determined to be effective; otherwise, it is ineffective. For nodes that are initially effective, the data is first summarized and fed back to human staff, and then node-by-node testing is performed: the average data upload latency rate of sensors is measured, the data forwarding packet loss rate of gateways is measured, and the command execution accuracy of controllers is measured. If all tests pass, the preliminary verification is completed; otherwise, it is marked for supplementation and secondary testing. Finally, if the re-evaluation score decrease still meets the standard after the preliminary verification, it is determined to be ultimately effective and a report is generated; otherwise, an alarm is issued to initiate emergency human intervention. This process accurately judges the intervention effect through dual verification of scoring comparison and node-by-node functional testing, avoiding misjudgment based on a single score. Node-by-node testing covers core functions to ensure that nodes fully recover to normal, while linking human review and emergency mechanisms to improve the reliability of verification.

[0015] 5. In analyzing the stability of node network links, this invention first collects link delay fluctuation values ​​and link reconnection counts according to a preset collection duration and number of cycles after receiving the effective verification results of the intervention. Then, it retrieves the corresponding link fluctuation correction coefficients from the database to correct the impact of risk states on link fluctuations. Finally, it calculates the percentage deviation between these two values ​​and their corresponding reference values, and weights and averages these deviation percentages with the correction coefficients to obtain a network link fluctuation score that quantifies the overall link fluctuation level. This process achieves accurate quantification of link stability by collecting key link parameters, introducing correction coefficients, and weighting and calculating fluctuation scores. It solves the problem of relying solely on a single parameter to judge link status. Furthermore, by combining analysis with the node status after intervention, it can accurately capture potential risks in the link after intervention, providing a scientific basis for subsequent secondary adjustments and ensuring the coordinated and stable operation of nodes and links.

[0016] 6. When determining whether secondary link stability adjustment is needed, this invention first checks if the network link fluctuation score is not greater than a preset reference value. If so, it is recorded as no secondary adjustment is needed, and a command to maintain connection stability is sent. Otherwise, it is recorded as requiring secondary adjustment, and a start signal and risk assessment report are generated. The score deviation is synchronized to the management terminal. After initiating secondary adjustment, the fluctuation score is retrieved. If the score meets the standard, a stability command is sent; otherwise, the decision is updated. The decision update requires comparing the retrieved score and deviation with the allowable range of link fluctuation after secondary adjustment. If the range is exceeded, secondary adjustment is restarted until the standard is met; if the range is not exceeded, an early warning is issued to allow maintenance personnel to investigate hardware failures, external interference, etc. This process ensures that link stability meets the standard while avoiding over-adjustment. When the adjustment does not meet expectations, differentiated handling is performed. It relies on continuous optimization through technical means and timely manual investigation to effectively solve potential link fluctuation risks, ensure reliable node network transmission, and improve the operational stability of the industrial IoT system. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A flowchart illustrating the IoT node security risk assessment and early warning method based on big data provided in this embodiment of the invention;

[0019] Figure 2 A flowchart illustrating the generation of risk intervention and adjustment signals provided in an embodiment of the present invention;

[0020] Figure 3 A flowchart for node network link stability analysis and secondary adjustment determination provided in an embodiment of the present invention;

[0021] Figure 4 A schematic diagram of the structure of the IoT node security risk assessment and early warning system based on big data provided in an embodiment of the present invention;

[0022] Figure 5 This is one of the schematic diagrams of an IoT security maintenance platform for a big data-based IoT node security risk assessment and early warning system provided in an embodiment of the present invention.

[0023] Figure 6 The second schematic diagram of the IoT security maintenance platform for the IoT node security risk assessment and early warning system based on big data provided in this embodiment of the invention;

[0024] Figure 7 This is one of the schematic diagrams illustrating the node network link stability analysis and secondary adjustment judgment process in the IoT security maintenance platform provided in this embodiment of the invention;

[0025] Figure 8 This is the second schematic diagram of the node network link stability analysis and secondary adjustment judgment process in the IoT security maintenance platform provided in this embodiment of the invention. Detailed Implementation

[0026] The technical solution of the present invention will now be described with reference to the accompanying drawings.

[0027] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.

[0028] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0029] This invention provides a method for assessing and warning of security risks of IoT nodes based on big data, such as... Figure 1 The flowchart shown is for a big data-based IoT node security risk assessment and early warning method. The processing flow of this method may include the following steps:

[0030] Step one involves collecting data from IoT nodes at a preset collection cycle to obtain node operation data reflecting the real-time operating status of the IoT nodes within that cycle. Simultaneously, a node security risk assessment is conducted to determine the early warning execution process for the IoT nodes. IoT nodes are terminal devices in an industrial IoT system with data acquisition, transmission, or control functions, typically including sensor nodes, controller nodes, and gateway nodes. Sensor nodes collect physical quantities or environmental parameters from the industrial site (such as temperature, pressure, vibration, humidity, equipment operating current, etc.), converting physical signals into transmittable digital signals. Controller nodes receive control commands from the system and, combined with real-time data from sensors, perform operations such as starting / stopping and parameter adjustment on industrial equipment (such as motors, valves, production line robotic arms, etc.). Gateway nodes connect different types of networks (such as the local area network of the sensing layer where sensors reside, the control layer network where controllers reside, and the wide area network of the cloud platform), enabling data interaction between different network layers. By accurately collecting the operation data of these three types of nodes, the data acquisition, control, and transmission stages of the industrial IoT system can be comprehensively covered, providing complete data support for subsequent risk assessments.

[0031] Step two: When the early warning execution process of a node is determined to be risk intervention and adjustment, risk intervention and adjustment are carried out based on the security risk assessment results of each IoT node, generating a risk intervention and adjustment signal, and verifying the effectiveness of the intervention and adjustment. The effectiveness verification not only focuses on the reduction of risk score, but also verifies the core capabilities of the node through functional testing, such as sensor data transmission latency and gateway data forwarding packet loss rate, to ensure that the intervention measures not only solve the current risk, but also do not affect the normal function of the node.

[0032] Step 3: When the intervention and adjustment are verified to be effective, perform a node network link stability analysis to determine whether a secondary adjustment is needed to improve network link stability. If so, determine whether to send a command to maintain the stability of the node network connection after the secondary adjustment. Otherwise, directly generate an IoT node risk assessment report to visualize the IoT node security risk assessment process and intervention effect. This helps operations and maintenance personnel to intuitively grasp the full process of assessment, intervention and link protection. The report also supports export and archiving, providing a reference case for subsequent handling of similar node risks and forming a closed loop of security management.

[0033] In this embodiment, the shortcomings of existing technologies are effectively addressed by linking node evaluation, intervention verification, and link analysis throughout the entire process: it ensures the comprehensiveness of the evaluation by covering data collection from three types of nodes, guarantees the effectiveness of intervention through functional testing, and, more importantly, adds link stability analysis and secondary adjustment to eliminate link blind spots, accurately determine whether the link after intervention is suitable for the node's operational needs, clearly present the correlation between node security and transmission reliability, significantly improve the overall security guarantee capability of the industrial IoT system, and archive the report to provide a reference for subsequent handling, forming a management closed loop.

[0034] like Figure 2 The flowchart for generating risk intervention and adjustment signals, as shown, follows this logic: First, obtain the number of running nodes and determine if it falls within the assessment range. If it does, it's considered a non-essential security risk assessment, and monitoring continues. If not, check if it's less than the minimum value in the range. If less, it's recorded as a first essential security risk assessment; otherwise, it's recorded as a second essential security risk assessment. The second essential assessment requires obtaining a security risk score and classifying its level. Next, determine the early warning execution process. If the process is not risk intervention and adjustment, maintain monitoring and generate a security status report. If it is, obtain the risk intervention parameter configuration table and retrieve the fields. If it's activated, match the intervention parameters with the peak score; if it's not activated, match the intervention parameters with the current security risk score. Finally, generate a risk intervention and adjustment signal and send it to the node management terminal to verify its effectiveness.

[0035] Further understanding is needed regarding the node security risk assessment process, which includes: retrieving pre-configured reference node operation data from the database to determine whether the acquired node operation data meets the risk assessment criteria; if the acquired node operation data falls within the range corresponding to the reference node operation data, it indicates that the current data interaction status of the IoT node is changing smoothly, with low potential security risks, and the node security risk assessment result is recorded as a non-essential security risk assessment. The node operation data includes network traffic data reflecting the node's data interaction, device status parameter data characterizing the device's hardware and software status, and log data recording node operations and abnormal events.

[0036] Otherwise, it indicates that the current data interaction status of the IoT node is changing abnormally, and there is a high possibility of security risks: If the amount of node running data acquired is less than the minimum value of the corresponding range of reference node running data, it may be due to node hardware failure (such as data acquisition module damage, sensor offline), network connection interruption (such as link disconnection, gateway failure causing data transmission failure), or software function abnormality (such as acquisition program lag, process crash), resulting in data acquisition or transmission interruption, and the node security risk assessment result is recorded as the first necessary security risk assessment; If the amount of node running data acquired is greater than the maximum value of the corresponding range of reference node running data, it may be due to external malicious attacks (such as DDoS attacks, malicious traffic injection), software abnormalities (such as log surge, redundant processes occupying resources), or parameter configuration errors, resulting in an abnormal surge in data volume, and the node security risk assessment result is recorded as the second necessary security risk assessment, with the second necessary security risk assessment having a higher priority than the first necessary security risk assessment.

[0037] When the node security risk assessment result is the first necessary security risk assessment, the designated personnel are prompted to prioritize checking the node's hardware power-on status, network link connectivity, and the running process of the data acquisition software, and synchronize this information to the node management terminal. When the node security risk assessment result is the second necessary security risk assessment, the security risk score of the IoT node is calculated based on the abnormal data volume reduction target corresponding to the second necessary security risk assessment, and a security risk level is classified. The node security risk assessment result reflects the security status of the IoT node within the preset data acquisition period. The abnormal data volume reduction target reflects the expected reduction standard for the node's running data volume that exceeds the maximum value of the interval corresponding to the reference node's running data volume. The security risk score quantifies the degree of abnormality of the current IoT node's security risk. The security risk level includes controllable and uncontrollable levels.

[0038] The aforementioned database is a database established before the design of the IoT node security risk assessment and early warning method based on big data to store various set data and historical data. The database includes, but is not limited to, pre-configured reference node operating data volume (including the corresponding minimum and maximum values ​​of the interval) and operating data characteristic parameters of different node types (sensors / controllers / gateways). Among them, the reference node operating data volume (including the minimum and maximum values ​​of the interval) is directly set by technical personnel.

[0039] The setup is based on the following: First, statistical analysis is conducted on the historical fluctuation range of network traffic data, device status parameter data, and log data of each node under normal operating conditions within a preset collection period in similar industrial scenarios. The lower limit of the historical fluctuation range is corrected and used as the minimum value of the interval (e.g., the historical lowest value after removing extremely low data volumes), and the upper limit is corrected and used as the maximum value of the interval (e.g., the historical highest value after removing extremely high data volumes). At the same time, the minimum and maximum values ​​of the interval of reference node operating data in the database can also be debugged and fine-tuned by technical personnel according to actual conditions such as changes in system operating load and node hardware iteration upgrades, to ensure that the reference values ​​can adapt to the dynamic changes in node operating status and provide an accurate judgment benchmark for risk assessment.

[0040] In this embodiment, node security risk assessment is divided into necessary and unnecessary categories. This avoids over-assessment of normally functioning nodes, reduces system resource consumption, and allows maintenance efforts to focus on abnormal nodes. The necessary assessment is further divided into first and second categories because the risk nature and urgency of the two types of anomalies differ: the first category (too low data volume) is mostly due to hardware or connectivity issues, affecting the continuity of data collection; the second category (too high data volume) may involve malicious attacks, threatening overall system security, and has a higher priority.

[0041] This tiered approach enables differentiated risk management, ensuring that no abnormal nodes are overlooked and prioritizing high-risk hazards for immediate handling, thereby improving risk response efficiency and precisely matching the dual requirements of industrial IoT systems for safety and operational efficiency.

[0042] Furthermore, the security risk score of the IoT node is calculated as follows: The degree of risk deviation for each parameter is obtained based on the security risk monitoring parameters of the IoT node. This includes the degree of abnormal connection risk deviation, used to quantify the severity of the risk of external network attacks on the IoT node, and the degree of log anomaly risk deviation, used to quantify the severity of security risks caused by internal operational anomalies in the IoT node. The security risk monitoring parameters include the frequency of port connections under unauthorized network access and the number of error codes generated in the log records during permission verification failure scenarios. The obtained degree of risk deviation is normalized, and the corresponding weights from the risk weight parameter set (including the weights of abnormal connection risk deviation and log anomaly risk deviation) are introduced and weighted together with the normalization results to obtain the security risk score.

[0043] The deviation degree of abnormal connection risk is represented by: calculating the difference between the actual port connection frequency under unauthorized network access and the allowed port connection frequency, and then using the ratio of this difference to the allowed port connection frequency as the deviation degree. The larger the value, the higher the risk of external attacks. The deviation degree of log anomaly risk is represented by: calculating the difference between the actual number of error codes generated due to failed permission verification in the logs and the allowed number of error codes generated, and then using the ratio of this difference to the allowed number of error codes generated as the deviation degree. The larger the value, the higher the risk of internal operational anomalies. The allowed port connection frequency and the allowed number of error code generation are respectively represented by the average of the historical allowed port connection frequency and the historical allowed number of error code generation in the historical IoT node security risk assessment process in the database.

[0044] If the deviation of abnormal connection risk increases, it may lead to frequent failures in internal permission verification, resulting in more error codes and a higher degree of log deviation. Conversely, a higher degree of log abnormal risk deviation may also expose node vulnerabilities and increase the risk of external abnormal connections, thus increasing the overall security risk of the node. This example eliminates differences in the magnitude of different parameters through normalization, making them directly comparable; it comprehensively covers risk dimensions by combining port connection frequency (external attacks) and error code count (internal anomalies); weighted processing reflects the priority of different risks, and the final score can accurately quantify the overall risk, providing a reliable basis for tiered handling.

[0045] In this example, the weights for the deviation levels of abnormal connection risk and log anomaly risk are pre-defined quantitative values ​​in the database representing the impact of these two types of risk deviations on the overall security risk of IoT nodes. Specifically, the database stores pre-defined weight values ​​corresponding to abnormal connection risk and log anomaly risk. These weight values ​​have a pre-defined mapping relationship with the impact of the two types of risks; this mapping relationship can be one-to-one or many-to-one. For example, in practical applications, based on the security requirements of industrial IoT scenarios (such as nodes involving core production data, where external attack risks are more significant), the scenario type can be input into this mapping relationship to quickly obtain the corresponding weight values. In this example, the values ​​for the deviation levels of abnormal connection risk and log anomaly risk are typically between 0 and 1, and their sum is 1, ensuring that after weighted coupling processing, the security risk score can reasonably quantify the overall risk level.

[0046] Specifically, the security risk level classification is as follows: if the obtained security risk score is within the allowable range set by preset personnel, the security risk corresponding to the IoT node is marked as controllable, and the early warning execution process is determined to maintain data monitoring for the preset collection period and generate a weekly security status report simultaneously; otherwise, the security risk corresponding to the IoT node is marked as uncontrollable, and the early warning execution process is determined to immediately initiate risk intervention and adjustment, and simultaneously trigger high-frequency data monitoring and operation and maintenance alarms.

[0047] In this embodiment, by comparing the security risk score with a preset allowable range, a clear definition of the risk level is achieved, avoiding delays or excessive intervention caused by ambiguous judgments. Regular monitoring and weekly reports are generated for controllable risks, ensuring dynamic manageability of nodes while reducing unnecessary consumption of maintenance resources. For uncontrollable risks, immediate intervention and high-frequency monitoring are initiated, enabling rapid response to high-risk hazards and preventing the risk from spreading and affecting the operation of the industrial IoT system. This tiered handling mechanism precisely matches the response needs of different risks, allowing maintenance personnel to clearly define priorities and improve the efficiency of risk handling. Simultaneously, standardized judgment logic ensures a unified and standardized risk level classification for different nodes, providing a reliable basis for subsequent intervention measures.

[0048] Furthermore, risk intervention and adjustment signals are generated, specifically as follows: Using the necessary security risk assessment identifier and security risk score from the node security risk assessment results as an index, the corresponding risk intervention parameter configuration table is retrieved from the database. This table stores IoT node fields containing "activated" and "deactivated" identifiers to visualize the differences in intervention strategies under different security risk levels. The table stores differentiated parameters in segments based on score values ​​(e.g., 61-70, 71-85, 86-100), with higher scores indicating stricter parameter control. From the risk intervention parameter configuration table, the field corresponding to the risk trend tracking status of the IoT node is retrieved: if the retrieved field displays an "activated" identifier, it indicates that the corresponding IoT node... The node has previously triggered the risk trend tracking process, generated a real-time scoring sequence, and obtained the peak risk score in the real-time scoring sequence. The obtained peak risk score is matched with intervention parameters to avoid insufficient intervention due to a temporary drop in the current score. If the retrieved field shows an "not started" flag, it means that the corresponding IoT node has not previously entered the trend tracking process and has no real-time scoring sequence. The current security risk score is then matched with intervention parameters. A risk intervention adjustment signal is generated based on the matched intervention parameters and sent synchronously to the node management terminal to form an intervention operation traceability file. At the same time, the intervention adjustment completion signal generation mechanism is triggered. After the operation is completed, a risk intervention adjustment completion signal is automatically generated to trigger the intervention adjustment effectiveness verification process.

[0049] The specific process for verifying the effectiveness of intervention and adjustment is as follows: After detecting the signal that the risk intervention and adjustment is completed, the node operation data is re-collected and the re-evaluation safety risk score is calculated based on the node safety risk score. If the decrease in the re-evaluation safety risk score compared with the baseline score before intervention is not less than the decrease set by the preset personnel, the intervention and adjustment are initially determined to be effective; otherwise, the intervention and adjustment are initially determined to be ineffective. The IoT nodes that are initially determined to be effective in intervention and adjustment are marked as pending verification. The verification data is initially summarized and manually fed back to the operation and maintenance personnel so that they can initially grasp the intervention effect and the current risk status of the nodes.

[0050] The peak risk score is obtained from the real-time score sequence generated after the node triggers the risk trend tracking process: the real-time score sequence records the node's security risk score at a preset collection interval (e.g., 1 minute / time). The system traverses the sequence and filters out the maximum value among all scores, which is the peak risk score, which can intuitively reflect the highest level of node risk.

[0051] In this embodiment, the node risk trend tracking status (activated / not activated) can be retrieved by field, which can accurately distinguish the historical risk monitoring status of the node: for nodes that have activated trend tracking, the peak risk score in the real-time scoring sequence is used to match the parameters. The core reason is that the current score may temporarily decrease due to attack pauses, software temporary recovery, etc. If only the current score is matched, it is easy to lead to overly loose control of intervention parameters, which cannot completely solve the high-risk problems that existed before. The peak score can reflect the upper limit of node risk, ensuring that intervention measures cover the maximum risk.

[0052] It is important to understand that risk intervention and adjustment of IoT nodes often adopts a model of matching current scores with fixed strategies: usually based on the node's real-time security risk score, a pre-set tiered intervention strategy table is retrieved from the database (such as basic protection, intermediate protection, and advanced protection corresponding to the score range), and standardized adjustment signals (such as port blocking, permission reset, traffic restriction, etc.) are directly generated and issued for execution. This helps to reduce the cost of strategy design and execution, and is suitable for basic risk management in large-scale IoT scenarios, ensuring the basic needs of node security.

[0053] However, the innovation of this example lies not in the risk intervention and adjustment itself, but in the design of the effectiveness verification after the intervention and adjustment: First, it clearly uses the pre-intervention score as the benchmark, and determines the effectiveness by comparing the reduction of the re-evaluation score with the benchmark score (not less than the set reduction), avoiding the problem of vague verification standards in existing technologies; Second, it marks the nodes that are initially determined to be effective as pending verification, and conducts data aggregation and manual feedback simultaneously. This not only makes up for the shortcomings of existing technologies that rely solely on automatic system judgment and lack manual intervention verification, but also allows operation and maintenance personnel to intuitively grasp the intervention effect, providing a more reliable decision-making basis for subsequent risk management and forming a complete closed loop of adjustment, verification, and feedback.

[0054] Further, preliminary data collection and manual feedback are conducted, followed by preliminary validity verification. The specific steps are as follows: For the sensor nodes, a data upload latency test command is sent to determine whether the sensor node data transmission function verification has passed. Specifically, a 1-minute test cycle is set, and the latency of the sensor node transmitting data to the gateway is continuously collected within 3 cycles. The average latency rate is calculated, and the result is compared with a preset qualified reference value (e.g., ≤50ms). If the average latency rate is ≤ the reference value, the sensor node data transmission function verification is considered to have passed.

[0055] For the gateway node, a data forwarding packet loss rate test command is sent to determine whether the gateway node's data forwarding function verification has passed. Specifically, 100 standard test data packets are sent to the gateway node, the number of data packets that are not successfully received during the forwarding process is counted, and the packet loss rate is calculated (packet loss rate = number of lost data packets / total number of sent data packets). If the packet loss rate is ≤ the preset qualified reference value (e.g., ≤ 1%), the gateway node's data forwarding function verification is considered to have passed.

[0056] For the controller node, a command execution accuracy test command is sent to determine whether the controller node command execution function verification has passed. Specifically, 10 preset control commands (such as status query) are sent, the number of successful command executions is counted, and the accuracy is calculated (accuracy = number of successful executions / total number of commands). If the accuracy is ≥99%, the controller node command execution function verification is considered to have passed.

[0057] If all functional test results for the corresponding node pass verification, the initial effectiveness verification is completed. If any functional test result fails verification, it is marked as requiring supplementary verification and fed back to the manual operation and maintenance end to trigger a second test. If the re-evaluation security risk score value obtained after the initial effectiveness verification decreases by no less than the decrease set by the preset personnel, the intervention adjustment is finally determined to be effective, and an intervention adjustment effectiveness verification pass report is generated. Otherwise, it indicates that there is an anomaly in the intervention function and a risk escalation alarm is sent to the operation and maintenance personnel to start the emergency manual intervention process.

[0058] In this embodiment, the core innovation of this step does not focus on the subsequent process of verifying whether it passes, nor is it limited to the specific values ​​set in the text (such as sensor latency ≤50ms, gateway packet loss rate ≤1%). These values ​​can be flexibly adjusted according to the actual needs of the Industrial Internet of Things (such as lower latency required for high-precision production scenarios, and packet loss rate can be appropriately relaxed for massive data transmission scenarios) and the performance of node hardware (such as older sensors needing to be adapted to higher latency reference values).

[0059] Its key innovation and focus on effectiveness lies in constructing a dual validity determination mechanism that combines functional testing and score reduction verification: First, it conducts node-specific functional tests (sensor latency testing, gateway packet loss testing, and controller accuracy testing) to ensure that intervention measures have not damaged the core operational functions of the nodes; then, it compares the score reduction in the re-evaluation with the set reduction to verify whether the risk has truly been reduced. This determination method avoids the one-sidedness of only looking at the score reduction while ignoring the damage to node functions, ultimately achieving the dual goals of risk control and node function protection. It provides a reliable basis for the accurate assessment of subsequent intervention effects and is adapted to the dual requirements of node security and operational stability in industrial scenarios.

[0060] like Figure 3 The flowchart shown illustrates the node network link stability analysis and secondary adjustment determination process. Its design logic is as follows: After receiving the effective verification results of intervention and adjustment, the monitoring parameter set is first acquired. Combined with link latency fluctuations, reconnection counts, and corresponding correction coefficients, a network link fluctuation score is calculated. Next, it is determined whether the score is not greater than a preset reference value. If yes, a command to maintain node network connection stability is sent; otherwise, a secondary adjustment initiation signal is generated and the process is initiated. After secondary adjustment, the fluctuation score is reacquired, and it is again determined whether it is not greater than the reference value. If yes, a maintenance command is sent; otherwise, a decision update is performed to determine the subsequent link stability optimization direction. Overall, the network link stability is ensured through the score determination and secondary adjustment mechanism.

[0061] Further understanding is needed regarding the node network link stability analysis. The specific process includes: after receiving the verification result confirming the effectiveness of intervention and adjustment, collecting a set of monitoring parameters for the network link to which the IoT node belongs, with a preset collection interval (e.g., 1 minute) and a preset number of cycles (e.g., 5 minutes). This includes link delay fluctuation values ​​reflecting the stability of the network link transmission process and the number of link reconnections reflecting the reliability of the physical connection. Each collection interval within the collection cycle has an equal duration. The link delay fluctuation value represents the standard deviation of the transmission delay between the IoT node and the communication object (e.g., gateway, other IoT nodes) within the collection cycle, and the number of link reconnections represents the total number of successful reconnections after a connection interruption between the IoT node and the network link within the collection cycle. The link fluctuation correction coefficients corresponding to the link delay fluctuation value and the number of link reconnections are obtained from the database to correct the impact of network link risk status on network link fluctuations. The deviation ratios of the link delay fluctuation value and the number of link reconnections from their corresponding reference values ​​are calculated. Each deviation ratio is weighted with its corresponding link fluctuation correction coefficient and then harmonic averaged to obtain a network link fluctuation score used to quantify the overall fluctuation level of the network link.

[0062] Specifically, an increase in link latency fluctuation indicates decreased transmission stability, which can easily lead to data transmission timeouts and connection interruptions, thus increasing the number of link reconnections. Conversely, an increase in the number of link reconnections indicates decreased physical connection reliability. The time consumed during the reconnection process further exacerbates the fluctuation in transmission latency. The interaction between these two factors significantly increases the overall volatility risk of the network link, affecting the stability of node data transmission. Reference values ​​include reference link latency fluctuation and reference link reconnection counts, which are represented by the average of historical link latency fluctuation and historical link reconnection counts obtained from historical node network link stability analysis in the database. Link volatility correction coefficients include link latency fluctuation correction coefficients and link reconnection count correction coefficients, which are obtained as follows:

[0063] The database stores preset link fluctuation correction coefficients (including link delay fluctuation correction coefficients and link reconnection count correction coefficients) closely related to link stability analysis. These correction coefficients establish a predefined mapping relationship with the corresponding link layer (such as the perception layer or control layer) and node function type (sensor / controller / gateway). It is worth noting that this mapping is not arbitrarily set; it can be a one-to-one correspondence or a many-to-one relationship. For example, in practical applications, when analyzing the stability of a node's network link, the real-time determined network layer and node function type can be directly input into this preset mapping relationship, enabling the rapid and accurate acquisition of link delay fluctuation correction coefficients and link reconnection count correction coefficients that match the current link scenario.

[0064] Most importantly, to ensure the reasonableness and accuracy of the link fluctuation score calculation, the link delay fluctuation correction coefficient and the link reconnection number correction coefficient in this example are both limited to the range of 0 to 1, and the sum of the two is 1.

[0065] In this embodiment, by collecting link delay fluctuation values ​​(standard deviation) and reconnection counts at fixed intervals and over multiple periods, the system accurately captures both link transmission stability and physical connection reliability while avoiding the randomness of single data collection, ensuring comprehensive and objective monitoring data. Introducing a link fluctuation correction coefficient eliminates interference from different network risk states on parameter analysis, making the calculation results more closely reflect actual link conditions. Through deviation ratio, weighted average, and harmonic mean processing, the two types of dispersed parameters are transformed into a unified link fluctuation score, achieving a quantitative assessment of link stability. This facilitates a direct judgment on whether the link meets the node's operational requirements after intervention. The overall process fills the gap in existing technologies that emphasize node assessment while neglecting link analysis, providing a scientific basis for subsequent secondary adjustment decisions, ensuring the continuous stability of data transmission in the industrial IoT system, and reducing the rebound of node security risks caused by link problems.

[0066] Furthermore, determine whether to perform secondary adjustments to improve network link stability, specifically:

[0067] If the obtained network link fluctuation score is not greater than the preset network link fluctuation score, it indicates that the link stability after intervention and adjustment meets the system operation requirements, and the secondary adjustment decision result is recorded as no secondary adjustment is needed. At the same time, an instruction to maintain the stability of the node network connection is sent. The preset network link fluctuation score is represented by the sum and average of the historical network link fluctuation scores in the historical IoT node stability analysis process in the database. Otherwise, it indicates that the network link still fluctuates, and the secondary adjustment decision result is recorded as requiring secondary adjustment. A secondary adjustment start signal is generated synchronously, and an IoT node risk assessment report is directly generated. The network link fluctuation score deviation is synchronized to the node management end. After receiving the secondary adjustment start signal, the secondary adjustment process is started. After the adjustment is completed, the network link fluctuation score is re-obtained. If the re-obtained network link fluctuation score is not greater than the preset network link fluctuation score, an instruction to maintain the stability of the node network connection is sent. Otherwise, it is determined that the secondary adjustment has not met expectations, and a decision update is performed to determine the direction of subsequent link stability optimization.

[0068] The decision update process specifically involves: after the secondary adjustment, re-acquiring the network link fluctuation score and its corresponding deviation, and comparing it with the allowed range of link fluctuation after the secondary adjustment (including the allowed range of fluctuation score and the allowed range of deviation) stored in the database. If the network link fluctuation score after the secondary adjustment is higher than the upper limit of the allowed range of fluctuation score, or the corresponding deviation of the network link fluctuation score is higher than the upper limit of the allowed range of deviation, the decision update is determined to restart the secondary adjustment process. After readjustment, the network link fluctuation score is acquired until the acquired network link fluctuation score is not greater than the preset network link fluctuation score. If the network link fluctuation score after the secondary adjustment and its corresponding deviation do not exceed the corresponding allowed range, the decision update is determined to send a link fluctuation warning to the manual operation and maintenance end, allowing operation and maintenance personnel to intervene and investigate potential problems such as link hardware failure and external interference. Otherwise, it indicates that the current node's network connection stability has far exceeded the expected standard, and there is no risk of abnormal link fluctuation.

[0069] The allowable range for fluctuation scores and the allowable range for deviations are set by pre-defined personnel based on the summation and average of the corresponding historical network link fluctuation scores and deviations in the database. The corresponding upper and lower limits of the ranges are represented by the summation and average of the maximum and minimum values ​​of the historical network link fluctuation scores and deviations in the decision update process of each historical network link in the database.

[0070] In this embodiment, the historical average fluctuation score is used as a reference value to ensure that the judgment standard aligns with the actual operating baseline of the system, avoiding misjudgments caused by overly strict or lenient reference values. Maintenance instructions are sent to compliant links to reduce unnecessary adjustment costs, while secondary adjustments are initiated for non-compliant links, with reports generated simultaneously to ensure risk traceability. The decision-making update process further achieves refined control through a three-tiered approach: repeated adjustments until compliance is achieved when the limit is exceeded, ensuring a baseline of link stability; manual checks are triggered when the link is within the allowable range to proactively mitigate hidden risks such as hardware and external interference; and no risk is confirmed within the allowable range to avoid excessive intervention. The overall process covers various scenarios of link fluctuations and, through dynamic adjustments and manual intervention, effectively ensures continuous and stable data transmission across industrial IoT nodes, improving the overall reliability of the system's safe operation.

[0071] This invention provides a big data-based IoT node security risk assessment and early warning system, such as... Figure 4 The diagram shows the structure of a big data-based IoT node security risk assessment and early warning system. The system's processing flow can include: a node security risk assessment and early warning execution process determination module, a risk intervention and effectiveness verification module, and a node network link stability analysis and secondary adjustment judgment module. The node security risk assessment and early warning execution process determination module is used to collect data from IoT nodes at a preset collection period, obtaining node operation data reflecting the real-time operating status of IoT nodes within the preset collection period, and simultaneously performing node security risk assessment to determine the early warning execution process for IoT nodes. The risk intervention and effectiveness verification module is used to perform early warning analysis and secondary adjustment judgment on node network links. When the alert execution process determines that risk intervention and adjustment is required, risk intervention and adjustment are carried out based on the security risk assessment results of each IoT node, generating a risk intervention and adjustment signal, and verifying the effectiveness of the intervention and adjustment to ensure that the risk intervention measures effectively reduce the security risks of the nodes. The node network link stability analysis and secondary adjustment judgment module is used to perform node network link stability analysis when the intervention and adjustment are verified to be effective, in order to determine whether to carry out secondary adjustment to improve network link stability. If so, it determines whether to send an instruction to maintain the stability of the node network connection after the secondary adjustment; otherwise, it directly generates an IoT node risk assessment report to visualize the IoT node security risk assessment process and intervention effect.

[0072] In this embodiment, the system achieves significant benefits through the collaborative design of three major modules: node assessment, intervention verification, and link analysis. First, it forms a complete safety management closed loop, from node data collection and risk assessment to intervention adjustment and effectiveness verification, and then to link stability analysis and secondary adjustment judgment, avoiding risk omissions caused by process breakpoints. Second, it focuses on the full lifecycle security of industrial IoT nodes, covering both the node's own operational risks and supplementing link stability analysis. Third, it presents the full process effect through visual reports, combined with a dynamic adjustment mechanism, which can accurately reduce node risks and ensure stable link transmission, greatly improving the overall reliability and operation and maintenance efficiency of the industrial IoT system.

[0073] It is necessary to understand that, such as Figure 5 The diagram shown is one of the IoT security maintenance platforms for a big data-based IoT node security risk assessment and early warning system. Figure 6 The second schematic diagram of the IoT security maintenance platform for the IoT node security risk assessment and early warning system is shown. Figure 5 This is the homepage of the IoT security maintenance platform, which presents a global overview of system security. You can see core security indicators such as the total number of nodes, the status of high-risk nodes, the number of interventions and adjustments made that day, and the link stability rate. There is also a real-time ranking of high-risk nodes, which displays the node risk level, cause, and early warning process. Figure 6 It displays the trend of intervention and adjustment effectiveness over a recent period, providing an intuitive understanding of changes in intervention effectiveness and frequency. It also lists pending maintenance tasks, such as secondary adjustment verification and manual alarm troubleshooting, making it easier for maintenance personnel to grasp the intervention effect and pending tasks. Overall, it provides support for system security situation awareness and maintenance task management.

[0074] like Figure 7 The diagram shown is one of the schematic diagrams of the node network link stability analysis and secondary adjustment judgment process in the IoT security maintenance platform, such as... Figure 8 The second schematic diagram illustrates the node network link stability analysis and secondary adjustment judgment process in the IoT security maintenance platform. Figure 7 It is a stability analysis interface that allows you to query the link monitoring parameters of a specified node within a set period. It displays link latency fluctuations and other information through charts, and combines the link fluctuation score with a preset threshold to determine link stability. Figure 8 The system presents the results of secondary adjustment decisions, including whether secondary adjustment is needed and the execution instructions. It also lists the node's historical link adjustment records, covering adjustment measures, pre- and post-adjustment scores, and effect assessments. This allows for tracing the adjustment process and its effectiveness, providing a basis for link stability optimization and secondary adjustment decisions, and helping to ensure the stability of the node's network links.

[0075] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.

[0076] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0077] In various embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0078] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0079] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for security risk assessment and early warning of IoT nodes based on big data, characterized in that, The method includes: Step 1: Collect data from IoT nodes at a preset collection period to obtain the amount of node operation data that reflects the real-time operating status of IoT nodes within the preset collection period. At the same time, conduct node security risk assessment to determine the early warning execution process of IoT nodes. Step 2: When the early warning execution process of a node is determined to be risk intervention and adjustment, risk intervention and adjustment are carried out based on the security risk assessment results of each IoT node, a risk intervention and adjustment signal is generated, and the effectiveness of the intervention and adjustment is verified to ensure that the risk intervention measures effectively reduce the security risks of the node. Step 3: When the intervention and adjustment are verified to be effective, perform node network link stability analysis to determine whether to perform secondary adjustment to improve network link stability. If so, determine whether to send instructions to maintain node network connection stability after secondary adjustment. Otherwise, directly generate an IoT node risk assessment report to visualize the IoT node security risk assessment process and intervention effect. The stability analysis of the node network links includes the following specific steps: After receiving the verification result that the intervention and adjustment are finally effective, the monitoring parameter set of the network link to which the IoT node belongs is collected with a preset collection time interval and a preset number of cycles as the collection cycle. This includes the link delay fluctuation value, which reflects the stability of the network link transmission process, and the number of link reconnection times, which reflects the reliability of the physical connection of the network link. Obtain the link latency fluctuation value and the link reconnection number corresponding to the link fluctuation correction coefficient, which is used to correct the impact of network link risk status on network link fluctuation; Calculate the percentage of deviation between the link delay fluctuation value and the number of link reconnection and the corresponding reference value. Weight each percentage of deviation with the corresponding link fluctuation correction coefficient and perform harmonic averaging to obtain the network link fluctuation score used to quantify the overall fluctuation of the network link. The determination of whether to perform secondary adjustments to improve network link stability specifically involves: If the obtained network link fluctuation score is not greater than the preset network link fluctuation score, the secondary adjustment decision result is recorded as no secondary adjustment is needed, and an instruction to maintain the stability of the node network connection is sent. Otherwise, the decision result of the secondary adjustment is recorded as requiring secondary adjustment, and a secondary adjustment start signal is generated simultaneously, and an IoT node risk assessment report is generated directly. The network link fluctuation score deviation is synchronized to the node management end. After receiving the secondary adjustment start signal, the secondary adjustment process is started. After the adjustment is completed, the network link fluctuation score is reacquired. If the reacquired network link fluctuation score is not greater than the preset network link fluctuation score, then a command to maintain the stability of the node network connection is sent; otherwise, it is determined that the secondary adjustment has not met expectations and a decision update is performed. The decision update specifically refers to: After the second adjustment, the network link fluctuation score and the corresponding network link fluctuation score deviation are reacquired and compared with the allowable range of link fluctuation after the second adjustment stored in the database. If the network link fluctuation score after the second adjustment is higher than the upper limit of the allowable fluctuation score range, or the corresponding network link fluctuation score deviation is higher than the upper limit of the allowable deviation range, the decision is to restart the second adjustment process, and obtain the network link fluctuation score after readjustment until the obtained network link fluctuation score is not greater than the preset network link fluctuation score. If the network link fluctuation score after the second adjustment and the corresponding network link fluctuation score deviation do not exceed the corresponding allowable range, the decision is updated to send a link fluctuation warning to the manual operation and maintenance terminal. Otherwise, it indicates that there is no risk of abnormal link fluctuations.

2. The method for assessing and warning of IoT node security risks based on big data as described in claim 1, characterized in that, The node security risk assessment process includes the following steps: Retrieve the pre-configured reference node running data volume to determine whether the obtained node running data volume meets the risk assessment standard; If the obtained node operation data volume is within the range corresponding to the reference node operation data volume, the node security risk assessment result is recorded as a non-essential security risk assessment. The node operation data volume includes network traffic data volume reflecting node data interaction, device status parameter data volume characterizing device hardware and software status, and log data volume recording node operations and abnormal events. If the amount of node running data obtained is less than the minimum value of the interval corresponding to the amount of reference node running data, then the node security risk assessment result is recorded as the first necessary security risk assessment. If the amount of node running data obtained is greater than the maximum value of the interval corresponding to the amount of reference node running data, then the node security risk assessment result is recorded as the second necessary security risk assessment, and the priority of the second necessary security risk assessment is higher than the priority of the first necessary security risk assessment. When the node security risk assessment result is the first necessary security risk assessment, the preset personnel are prompted to prioritize checking the node hardware power-on status, network link connectivity, and the running process of the data acquisition software, and synchronize this information to the node management terminal. When the node security risk assessment result is the second necessary security risk assessment, the security risk score of the IoT node is calculated by combining the abnormal data volume reduction target corresponding to the second necessary security risk assessment, and the security risk level is classified at the same time. The node security risk assessment result is used to reflect the security status of IoT nodes within a preset collection period. The abnormal data volume reduction target is used to reflect the expected reduction standard of node operating data volume that is greater than the maximum value of the corresponding interval of the reference node operating data volume. The security risk score is used to quantify the degree of abnormality of the current IoT node's security risk. The security risk level includes controllable level and uncontrollable level.

3. The method for assessing and warning of IoT node security risks based on big data as described in claim 2, characterized in that, The security risk score for the calculated IoT node is specifically as follows: The degree of risk deviation of each parameter is obtained according to the security risk monitoring parameters of the IoT node. This includes the degree of risk deviation of abnormal connection, which is used to quantify the severity of the risk of IoT node facing external network attacks, and the degree of risk deviation of log abnormality, which is used to quantify the severity of the security risk caused by internal operation abnormality of IoT node. The security risk monitoring parameters include the frequency of port connection under unauthorized network access and the number of error codes generated in the log record under the scenario of permission verification failure. The obtained risk deviations are normalized, and the corresponding weights in the risk weight parameter set are introduced and weighted together with the normalization results to obtain the safety risk score. The security risk level classification is as follows: If the obtained security risk score is within the set allowable range, the security risk corresponding to the IoT node will be marked as controllable, and the early warning execution process will be determined to maintain the preset collection cycle for data monitoring and generate a weekly security status report simultaneously. Conversely, the security risks corresponding to IoT nodes will be marked as uncontrollable, and the early warning execution process will be determined as immediately initiating risk intervention and adjustment, and simultaneously triggering high-frequency data monitoring and operation and maintenance alarms.

4. The method for assessing and warning of IoT node security risks based on big data as described in claim 1, characterized in that, The generation of risk intervention and adjustment signals specifically includes: Using the necessary security risk assessment identifier and security risk score in the node security risk assessment results as an index, the corresponding risk intervention parameter configuration table is retrieved from the database. The risk intervention parameter configuration table stores IoT node fields containing activated and non-activated identifiers to visualize the differences in intervention strategies under different security risk levels. Retrieve the field corresponding to the risk trend tracking status of the IoT node from the risk intervention parameter configuration table: If the retrieved field shows an activated flag, then obtain the peak risk score in the real-time scoring sequence, and match the obtained peak risk score with the intervention parameters to avoid insufficient intervention due to a temporary drop in the current score. If the retrieved field displays an "not started" flag, then the intervention parameters will be matched with the current security risk score. Based on the matched intervention parameters, a risk intervention adjustment signal is generated and simultaneously sent to the node management terminal to form an intervention operation traceability file. At the same time, the intervention adjustment completion signal generation mechanism is triggered. After the operation is completed, a risk intervention adjustment completion signal is automatically generated to trigger the intervention adjustment effectiveness verification process.

5. The method for assessing and warning of IoT node security risks based on big data as described in claim 4, characterized in that, The specific process for verifying the effectiveness of the intervention is as follows: After detecting the signal that the risk intervention and adjustment is completed, the node operation data is re-collected and the re-evaluation safety risk score after intervention is calculated based on the node safety risk score. If the safety risk score in the reassessment decreases by no less than the set decrease compared to the baseline score before intervention, the intervention is preliminarily deemed effective; otherwise, the intervention is preliminarily deemed ineffective. IoT nodes that are initially determined to be effective for intervention and adjustment are marked as pending verification, and preliminary verification data is collected and manually fed back.

6. The method for assessing and warning of IoT node security risks based on big data as described in claim 5, characterized in that, The process involves initial data aggregation and manual feedback, followed by preliminary validity verification. The specific steps are as follows: For the sensor nodes, a data upload latency test command is sent to determine whether the sensor node's data transmission function verification has passed. For the gateway node, send a data forwarding packet loss rate test command to determine whether the gateway node's data forwarding function verification has passed; For the controller node, send an instruction execution accuracy test instruction to determine whether the controller node instruction execution function verification has passed; If all functional test results for a node pass verification, the initial validity verification is completed. If any functional test result fails verification, it is marked as needing further verification and fed back to the manual operation and maintenance end to trigger a second test. If the re-evaluation security risk score obtained after the initial effectiveness verification decreases by no less than the set decrease compared to the baseline score before intervention, the intervention is ultimately deemed effective, and an intervention effectiveness verification report is generated. Otherwise, it indicates that the intervention function is abnormal, and a risk escalation alarm is sent to the operations and maintenance personnel to initiate the emergency manual intervention process.

7. A big data-based IoT node security risk assessment and early warning system, employing any one of the big data-based IoT node security risk assessment and early warning methods as described in claims 1-6, comprising: The module includes a node security risk assessment and early warning execution process determination module, a risk intervention and adjustment and effectiveness verification module, and a node network link stability analysis and secondary adjustment judgment module. The node security risk assessment and early warning execution process determination module is used to collect data from IoT nodes at a preset collection period, obtain node operation data that reflects the real-time operating status of IoT nodes within the preset collection period, and at the same time perform node security risk assessment to determine the early warning execution process of IoT nodes. The risk intervention adjustment and effectiveness verification module is used to perform risk intervention adjustment based on the security risk assessment results of each IoT node when the early warning execution process of the node is determined to be risk intervention adjustment, generate risk intervention adjustment signals, and perform intervention adjustment effectiveness verification to ensure that the risk intervention measures effectively reduce the node security risks. The node network link stability analysis and secondary adjustment determination module is used to perform node network link stability analysis when the intervention adjustment is verified to be effective, in order to determine whether to perform secondary adjustment to improve network link stability. If so, it determines whether to send an instruction to maintain the stability of node network connection after the secondary adjustment. Otherwise, it directly generates an IoT node risk assessment report to visualize the IoT node security risk assessment process and intervention effect.

Citation Information

Patent Citations

  • Power Internet of Things security risk assessment method, system and device, and storage medium

    CN115034644A

  • A mine safety risk investigation method and system based on intelligent Internet of Things devices

    CN118966796B

  • Network security data risk assessment system based on Internet of Things

    CN116896481A

  • Internet of Things control system and safety early warning method

    CN120165916A