Intelligent equipment security multi-dimensional dynamic monitoring and early warning method and system
By digitizing device behavior chains, logicalizing scenarios, and visualizing risks, combined with TTP knowledge graphs and industrial-grade risk transmission models, the shortcomings of single-point alarms in smart home security systems are addressed, system immunity is achieved, and assessment efficiency and protection effectiveness are improved.
Patent Information
- Application Number
- CN202511840298.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-08
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2045-12-08
AI Technical Summary
Existing smart home security solutions are insufficient in depth, breadth, and foresight. They lack the ability to deeply analyze device behavior chains and scene logic, cannot fully cover potential attack scenarios, and are unable to achieve a qualitative leap from single-point alarms to system immunity.
By digitizing the device behavior chain, logicalizing the scenario, and visualizing the risk, combined with TTP knowledge graphs and industrial-grade risk transmission models, we can monitor the operation and status changes of smart devices in real time, identify abnormal sequences, simulate the propagation process of security risks in the network, and intuitively display the risk distribution through heat maps, providing automated and quantifiable assessment and early warning.
This represents a qualitative leap from single-point alarms to system immunity, improving the efficiency and coverage of security equipment assessment, quantifying protection effectiveness, reducing the workload of maintenance personnel, and enhancing the system's self-protection capabilities and the accuracy of risk prediction.
Smart Images

Figure CN121596859A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of smart home, and particularly relates to a method and system for multi-dimensional dynamic monitoring and early warning of the security of smart devices. Background Art
[0002] In the field of smart home, traditional security protection functions usually rely on alarms for individual devices or single events. For example: Risks such as gas leakage, smoke, and waterlogging are mainly monitored by specific sensors and alarms are issued.
[0003] Devices such as door locks and cameras also provide point-to-point security monitoring and response.
[0004] However, these traditional or basic smart home security methods have the following deficiencies and technical problems: Low evaluation efficiency and incomplete coverage: Traditional security device evaluation methods, especially for capabilities such as IP blocking, are inefficient and difficult to comprehensively cover all potential attack scenarios, making it difficult to comprehensively evaluate the overall effectiveness of security devices.
[0005] Lack of automated and quantifiable evaluation means: For security functions such as IP blocking deployed, an automated, repeatable, and quantifiable evaluation method is needed to verify its effectiveness and timely detect potential configuration defects or performance bottlenecks.
[0006] Limited to "single-point alarms": Existing systems mainly provide "single-point alarm" functions. This means that they can only issue alarms when specific events occur, lacking monitoring of the integrity and correctness of the entire device behavior chain. For example, although a smart home can achieve linkage functions such as automatically turning off lights and air conditioners in the "away mode", traditional methods cannot monitor whether these linkages are executed as expected or whether abnormalities occur during the execution process.
[0007] Difficulty in judging scenario logic problems: Traditional methods can only identify that "a certain device has a problem", but cannot deeply judge whether there are problems with the execution logic of "a certain scenario", resulting in a lack of context and depth in understanding security issues.
[0008] Lack of risk propagation analysis ability: Traditional security protection fails to introduce an industrial-level risk conduction model. This means that they cannot deeply analyze the propagation path and chain effects of faults or threats in complex smart home systems, making it difficult to predict the potential risks that a certain device being attacked may pose to the entire system.
[0009] Difficulty in understanding complex data: For smart home users without professional IT knowledge, it is a challenge to intuitively understand complex security data and quickly locate high-risk areas, and a more user-friendly risk visualization method is needed.
[0010] In summary, existing smart home security solutions are significantly lacking in depth, breadth, and foresight. They mainly remain at the stage of passive "single-point alarms," lacking the ability to deeply analyze behavioral chains and scene logic, as well as the ability to predict and systematically suppress risk transmission. Therefore, there is an urgent need for an innovative method that can achieve a qualitative leap from "single-point alarms" to "system immunity." Summary of the Invention
[0011] To address the aforementioned technical problems, this invention proposes a multi-dimensional dynamic monitoring and early warning method for smart device security, comprising the following steps: Continuously monitor all operations and status changes of smart devices in real time, digitize their behavior to form device behavior sequences, and identify abnormal sequences that deviate from the normal behavior patterns of smart devices. These abnormal sequences can be used as input for subsequent TTP prediction. The preset smart home scenario logic is transformed into an expected path model that can be used for security analysis, and compared with the abnormal sequence. The causal chain of the TTP knowledge graph is then used to determine whether the abnormal sequence constitutes a security risk. The comparison results and security risk status are presented intuitively in the form of a heatmap to show the risk distribution and intensity of devices or areas. It can also integrate the analysis of unprotected major disaster types generated by TTP prediction and the protection effect diagram based on the ATT&CK framework. In addition, the method uses a risk transmission model based on TTP knowledge graph enhancement to dynamically simulate the evolution and propagation process of the security risks in the smart device network, and integrates the attack paths and causal relationships predicted by TTP.
[0012] This invention also proposes a multi-dimensional dynamic monitoring and early warning system for smart device security, the system comprising: The device behavior chain digitization module is used to continuously monitor all operations and status changes of smart devices in real time, digitize their behavior to form a device behavior sequence, and identify abnormal sequences that deviate from the normal behavior pattern of smart devices. The abnormal sequences can be used as input for subsequent TTP prediction. The scene logic module is used to transform the preset smart home scene logic into an expected path model that can be used for security analysis, compare it with the abnormal sequence, and combine it with the causal chain of the TTP knowledge graph to determine whether the abnormal sequence constitutes a security risk. The risk visualization module is used to visually present the comparison results and security risk status in the form of a heat map, which is used to show the risk distribution and intensity of devices or areas. It can also integrate the analysis of unprotected major disaster types generated by TTP prediction and the protection effect diagram based on the ATT&CK framework. In addition, in the system, the risk transmission model based on TTP knowledge graph enhancement dynamically simulates the evolution and propagation process of the security risks in the smart device network, and integrates the attack paths and causal relationships predicted by TTP.
[0013] The solution of this invention can bring about the following technical effects: The solution of this invention can automatically evaluate the IP blocking capabilities of security devices, which greatly improves evaluation efficiency and coverage compared with traditional manual testing.
[0014] The solution of this invention can quantify the IP blocking capabilities of security devices, allowing users to understand the protection effect more intuitively.
[0015] The solution of this invention can be used to regularly evaluate the ability to block IPs, promptly identify potential configuration defects or performance bottlenecks, and make optimizations and adjustments.
[0016] By employing the solution of this invention, automated assessment reduces the workload of operations and maintenance personnel, allowing them to focus more on strategy optimization and risk response, thereby improving the efficiency of security operations and maintenance.
[0017] The solution of this invention achieves a qualitative leap from "single-point alarm" to "system immunity" through a "three-stage leap" of digitizing the equipment behavior chain, logicalizing the scenario, and visualizing the risk, and for the first time introduces an industrial-grade risk transmission model. This means that the system not only responds to risks that have already occurred, but also has the ability to protect itself and recover, thus possessing a higher level of "immunity" to various potential threats.
[0018] The present invention constructs a dynamic security early warning system based on device behavior chains, which can monitor all operations and state changes of intelligent devices in real time, digitize them into device behavior sequences, and identify abnormal sequences. This comparison elevates security monitoring from merely responding to single events to monitoring the integrity and correctness of the entire device behavior chain, achieving more dynamic and comprehensive security early warnings.
[0019] The solution of this invention can transform the preset smart home scene logic into a predictable path model that can be used for security analysis, and compare it with abnormal sequences to determine whether there are problems with the execution logic of the scene, thereby improving the accuracy and severity of the warning. This achieves an improvement from "knowing that a certain device has a problem" to "knowing that the execution logic of a certain scene has a problem".
[0020] The present invention applies an industrial-grade risk transmission model to the smart home field for the first time. This model uses stock, traffic, auxiliary variables, and feedback loops to describe the security risk status of smart devices. It can dynamically simulate the evolution and propagation of security risks in smart device networks, thereby predicting risk propagation paths and evaluating the effectiveness of different defense strategies in suppressing risk propagation.
[0021] The solution of this invention can identify key nodes or super-spreaders in a smart home system, such as highly connected or highly vulnerable devices, and thus prioritize hardening these devices.
[0022] The solution of this invention presents the status of safety risks in the form of a heatmap, which displays the risk distribution and intensity of equipment or areas and visualizes the dynamic evolution of risks. This transforms complex safety data into intuitive graphics, making it easier for users to understand and take countermeasures, and helping them quickly locate high-risk areas.
[0023] The solution of this invention can automatically generate actionable safety improvement guidance suggestions based on multi-dimensional analysis results, which transforms "risk identification" into practical actions of "risk mitigation", greatly improving the efficiency and resilience of "system immunity".
[0024] The solution of this invention, by combining a large language model and a TTP knowledge graph, can predict attack paths of smart home systems in advance, thereby enhancing preemptive defense capabilities. The causal chains of the knowledge graph provide clear predictive basis, reduce the illusion of a large model, and improve the accuracy and interpretability of predictions.
[0025] By adopting the solution of this invention, real-time closed-loop optimization is achieved, and the knowledge graph and evaluation tasks are dynamically updated in real time by the positive and negative feedback loops, forming a continuously optimized closed-loop security management mechanism.
[0026] The solution of this invention, by combining IP blocking assessment and BAS comprehensive analysis, provides a comprehensive security insight and multi-dimensional collaborative analysis from the network layer to the system layer, significantly improving system immunity. Attached Figure Description
[0027] Figure 1 This is a schematic diagram of the multi-dimensional dynamic monitoring and early warning method for smart device security proposed in this invention.
[0028] Figure 2 This is a schematic diagram of the intelligent device security multi-dimensional dynamic monitoring and early warning system proposed in this invention. Detailed Implementation
[0029] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0030] This embodiment aims to elaborate on the specific implementation of a multi-dimensional dynamic monitoring and early warning method for intelligent device security, particularly the application of its core industrial-grade risk transmission model. It deeply integrates a TTP (Tactical, Technical, and Implementation Process) prediction scheme and a BAS (Breach and Attack Simulation) assessment system to achieve a qualitative leap from "single-point alarm" to "system immunity." The core working principle of this method is a "three-stage transition," namely, the digitization of device behavior chains (abnormal sequences), the logicalization of scenarios (expected paths), and the visualization of risks (heatmaps). Based on this, this scheme uses a risk transmission model enhanced with a TTP knowledge graph to dynamically simulate the evolution and propagation of security risks in intelligent device networks, integrating the attack paths and causal relationships predicted by TTP.
[0031] 1. Core Concepts of System Dynamics Model The core working principle of this multi-dimensional dynamic monitoring and early warning method for smart home security is a "third-order leap," aiming to achieve a qualitative leap from "single-point alarm" to "system immunity." Among its key innovations, the industrial-grade risk transmission model is applied for the first time in the smart home field, capable of dynamically simulating the evolution and propagation of security risks within a smart device network. It typically employs difference equations to simulate the changes in the risk inventory of each device.
[0032] This embodiment uses a simplified difference equation to simulate each device at the time step. Changes in the stock of internal risks:
[0033] in: For equipment In time The existing risk, This refers to the simulation time step. The model's parameters and dynamic simulation process can be enhanced and calibrated using the TTP knowledge graph and prediction results. Risk inflow rate:
[0034] and: Risk outflow rate:
[0035] Parameter definition: Risk propagation rate constant, reflecting the efficiency of risk diffusion.
[0036] : Defense and attenuation rate constant, reflecting the efficiency of risk reduction.
[0037] :equipment In time Risk inventory (e.g., 0-100).
[0038] :equipment arrive The network connection strength can be determined based on TTP correlation analysis (0-1, high indicates a tight connection).
[0039] Devices updated based on TTP knowledge graph and vulnerability information The inherent vulnerability (0-1, high indicates vulnerability to attack).
[0040] External targeting equipment Threats such as new vulnerability discoveries or direct attacks.
[0041] :equipment The defense strength (0 or 1, where 0 means no defense and 1 means that defense measures such as isolation or patching have been activated).
[0042] Its core is to use the following concepts to describe the dynamic behavior of the system: Stocks: Represent entities in a system that accumulate or are consumed over time. In a smart home security model, stocks can be represented as the "Risk Level" or "Vulnerability Count" for each smart device. For example, a device's "cumulative risk stock" may increase due to the discovery of new vulnerabilities or decrease due to patching.
[0043] Flows: Represent the rate at which a stock changes over time. Flows can be the "Risk Increase Rate" or the "Risk Propagation Rate." For example, after a device is attacked, its risk will flow to other devices in the network at a certain rate.
[0044] Auxiliary variables: These are the determinants of traffic. They are often functions of other variables. For example, a device's "risk propagation rate" might depend on the device's "current risk level," network connectivity strength based on TTP association analysis, and the vulnerability of neighboring devices updated by the TTP knowledge graph.
[0045] Feedback loops describe the mutual influence between variables.
[0046] Positive Feedback: A loop that amplifies risk. It can be used in conjunction with TTP (Tracking Points to Target) to predict potential attack paths and provide early warnings of system-level risks. For example, if device A is infected... An attacker uses device A to attack device B. The risk of device B increases. Device B, in turn, helps attack device C. The risks across the entire system are spreading rapidly.
[0047] Negative feedback: A loop that suppresses risk. It can provide precise intervention targets and guidance based on TTP prediction results. For example, device A is infected. The monitoring system detected an anomaly. Initiate isolation or repair mechanism The risk of device A is reduced, thereby inhibiting the further spread of the risk.
[0048] Suppose a smart home system includes the following core smart devices: D1: Smart door lock (typically connected to a Wi-Fi gateway, with high security requirements, which may include abnormal unlocking attempts or unauthorized firmware access).
[0049] D2: Smart camera (connected to a Wi-Fi gateway, which may be vulnerable and a potential stepping stone that could include unauthorized data transmission).
[0050] D3: Smart lighting system (connected to Wi-Fi gateway, usually with low security, but there are many of them. Once controlled, it may lead to privacy leaks or physical security risks, and may include abnormal lighting changes).
[0051] D4: Intelligent central control gateway (core network connection device, all device traffic passes through it, possessing the highest network connection strength) ).
[0052] Objective: To simulate how risks propagate in a smart door lock (D1) after an attack, and how defensive measures mitigate those risks.
[0053] This invention proposes a multi-dimensional dynamic monitoring and early warning method for the security of intelligent devices, such as... Figure 1 As shown, it specifically includes: Step S1 involves continuously monitoring all operations and status changes of smart devices in real time, digitizing their behavior to form device behavior sequences, and identifying abnormal sequences that deviate from the normal behavior patterns of smart devices. These abnormal sequences can be used as input for subsequent TTP prediction. The core of this step is that the system continuously monitors the operations and status changes of all smart devices in the smart home in real time, digitizes them to form device behavior sequences, and identifies abnormal sequences that deviate from the normal behavior patterns of smart devices. This is equivalent to real-time monitoring and pattern recognition of the actual, fine-grained device operations and status changes occurring in the smart home system. Specifically, this step includes: Data Acquisition: The system continuously collects sensor data and environmental parameters from smart devices, such as the on / off status of smart door locks, recording commands from smart cameras, and brightness adjustment records from smart lighting systems. This data constitutes the original "sequence" of device behavior. Anomaly Identification: By performing pattern recognition on these digitized sequences, potential security risks are quickly identified, such as unauthorized operations, abnormal status changes, or signs of device malfunction.
[0054] Example: When the smart door lock (D1) makes an abnormal unlocking attempt (such as multiple incorrect fingerprint recognitions within a short period of time) or unauthorized firmware access; or when the smart camera (D2) transmits data without authorization (such as uploading video to an external IP address in away mode); or when the smart lighting system (D3) experiences abnormal light changes. The system will identify these as "abnormal sequences". In this embodiment, at this stage, the "risk stock" of each device ( The threshold will increase based on the severity and frequency of the detected anomalous sequences. For example, after a smart lock identifies multiple anomalous attempts, The value will increase rapidly. The "abnormal sequences" identified in this step can be directly used as input data for subsequent TTP prediction schemes (combining large language models and TTP knowledge graphs). For example, the BAS system simulates attacks to generate alarm data, and this alarm data (i.e., abnormal sequences) is mapped to TTP entities in the knowledge graph, thereby initiating the prediction of potential attack paths. This transforms security monitoring from passive alerting to proactive predictive defense.
[0055] Step S2: The preset smart home scene logic is transformed into an expected path model that can be used for security analysis, and compared with the abnormal sequence. The causal chain of the TTP knowledge graph is then used to determine whether the abnormal sequence constitutes a security risk. This step aims to transform the preset scene function schemes in the smart home into "expected path" models that can be used for security analysis. These "expected paths" represent the expected and normal linkage relationships and operating procedures between devices in a specific scenario. The system compares the "abnormal sequences" (i.e., actual device behaviors that may deviate from normal behavior) identified in the previous stage with these "expected path" models to determine whether the abnormal sequence constitutes a security risk. In this embodiment, this specifically includes: Expected Path Modeling: Various "scene-based functionalities" meticulously planned in smart home solutions, such as "Home Mode," "Away Mode," or "Sleep Mode," can all be considered potential "expected paths." These paths define "what should happen" and "how it should happen" in specific scenarios. For example, the expected path for "Home Mode": When the smart door lock (D1) is unlocked from the outside, the expected triggering actions include: automatically turning on the entryway light and living room light (curtains may open during the day); automatically turning on the air conditioner and fresh air system and adjusting them to a suitable temperature; and controlling the robot vacuum to return to the home.
[0056] The expected path of "Away Mode": When the door is closed and locked from the outside, the expected triggering actions include: automatically turning off all the lights, air conditioning, fresh air system and other equipment in the house; controlling the window opener to close the windows (as needed); and controlling the robot vacuum cleaner to start working.
[0057] The expected path of "Sleep Mode" is: automatically turn off all lights and curtains in the room, and adjust the air conditioner temperature to the preferred sleep temperature.
[0058] Comparison and risk assessment: The system will compare the "abnormal sequence" detected in the "digitalization of device behavior chain" stage (step S1) with the above "expected path" model.
[0059] For example, if, after activating "Away Mode," the system detects anomalies such as the smart camera (D2) being controlled without authorization and transmitting data, or a light (D3) not turning off as expected, this deviates from the "expected path" of "Away Mode," and the system will determine that a security risk exists. This also applies when the smart lock (D1) exhibits anomalies with multiple unauthorized unlocking attempts, while the expected path of "Home Mode" is not triggered. This comparison elevates security monitoring from merely responding to a single event (such as a gas leak alarm) to monitoring the integrity and correctness of the entire behavioral chain.
[0060] Security risks are assessed by combining the causal chains of the TTP knowledge graph: when an abnormal sequence deviates from the expected path, this deviation (i.e., abnormal behavior) can be mapped to an initial TTP entity in the TTP knowledge graph. Through the causal chains of the TTP knowledge graph, the system can predict subsequent possible attack behaviors or potential attack paths. These predictions serve as important criteria for determining whether the abnormal sequence constitutes a security risk and its severity.
[0061] Specifically, when the comparison detects an abnormal sequence of unauthorized data transmission by the smart camera (D2) in "away mode", the system will map this behavior to a certain reconnaissance or data theft TTP entity in the TTP knowledge graph.
[0062] The TTP prediction scheme will utilize the causal chain mechanism of knowledge graphs to predict potential secondary or accompanying TTPs, such as "unauthorized data transfer" leading to "privilege escalation" or "data breach".
[0063] These predicted subsequent TTPs will significantly improve the system's risk assessment and severity evaluation of initial anomalous behavior. For example, if a data breach is predicted, the anomalous sequence constitutes a high-level security risk.
[0064] At this stage, when a security risk is identified through logical comparison of the scenario, the system will trigger defensive measures. For example, when an external attack risk is detected in the smart door lock (D1), its risk inventory... It will rise, and through its network connection strength with the intelligent central control gateway (D4) ) and the vulnerability of the gateway itself ( ), based on risk transmission rate The rate flows to D4. Once the risk stock in D4... Once it reaches a certain level, it will spread to other devices (such as D2 and D3) as a new source of risk.
[0065] Example of a positive feedback loop: If the smart camera (D2) is highly vulnerable (high... ) and was quickly invaded ( (Increase) An attacker could use D2 as a springboard to further attack other devices (such as D3), or even gain deeper control over D1, which would form a positive feedback loop and accelerate the spread of risk throughout the system.
[0066] Defense Triggering and Risk Outflow: Once a risk is identified and determined to be a security risk, the system will trigger defensive measures. For example, at a certain point in time... The system will assess the defense strength of high-risk devices (such as D1 and D2). It changes from 0 to 1. At this point, the risk outflow rate... It began to take effect, because It becomes 1, the risk outflow rate increases, and the equipment risk stock begins to decrease. In this step, by comparing the actual device behavior (abnormal sequence) with the preset normal operation logic (expected path) and conducting in-depth analysis in combination with the causal chain of the TTP knowledge graph, it can not only identify the anomalies of individual devices, but also judge its severity according to the scenario logic and predict the potential development of attacks, thus improving the accuracy of early warning and severity judgment. It realizes the upgrade from "knowing that there is a problem with a certain device" to "knowing that there is a problem with the execution logic of a certain scenario" and can predict the subsequent development path of the attack, which is the key link for the qualitative change of smart home security from "single-point alarm" to "system immunity".
[0067] In this embodiment, the types of attacks that smart devices may receive include: brute force cracking, that is, the attacker makes a large number of password or fingerprint attempts on the smart lock or camera in a short time; abnormal access: the smart camera is suddenly remotely activated during non-working hours at night, or the smart speaker is abnormally awakened when the user does not issue an instruction; malicious control: the smart curtain or lighting system receives frequent and irregular switch commands. For the above various attack means, we can adopt the following methods for protection: real-time behavior sequence analysis: the system continuously collects the "behavior sequence" of device operations. For example, in the "away mode", after the smart lock issues a door closing instruction, the system expects the curtain to close and the lights to go out. If the lock immediately receives multiple incorrect fingerprint instructions after closing the door, the system will mark it as an abnormal sequence. Scenario logic comparison: The system compares this abnormal sequence with the expected path models such as the preset "away mode". If it is found that it does not match the normal logic, such as frequent attempts on the lock in the "away mode", the system will immediately judge it as a potential risk and predict subsequent attacks in combination with the TTP knowledge graph. Moreover, we can also achieve security protection through multi-device linkage response. For example: when the smart lock detects multiple brute force cracking attempts, it will not only alarm itself, but also send an alarm to the main control gateway. The gateway will cooperate with other devices, such as: smart camera: immediately start recording and aim at the lock area. Smart lighting system: adjust the lights in the entrance hall to high brightness and flash to deter potential attackers. The smart speaker issues a warning, such as "Please stop the operation immediately". Risk conduction model: When the lock is attacked, the risk conduction model will analyze whether this risk will spread to other devices through the home network. For example, if there is a high-risk connection between the lock and the central control gateway, the system will predict that the risk stock of the central control gateway will increase and remind the user to strengthen the security measures of the central control gateway.
[0068] In this embodiment, the types of attacks that the smart device may receive also include vulnerability exploitation. For example, firmware vulnerabilities: attackers remotely obtain administrator privileges by exploiting known firmware vulnerabilities of smart routers (such as CVE-2023-XXXX); weak passwords / default passwords: attackers enter the device by scanning and exploiting the default weak passwords of smart cameras or smart sockets (such as "admin / 123456"). SQL injection: attackers exploit the Web interface vulnerabilities of the smart home control App to steal user data or tamper with device control instructions. For the above various attack methods, we can adopt the following methods for protection: TTP knowledge graph prediction: When it is found that a device (such as a router) has a known vulnerability, the system will use the causal chain of the TTP knowledge graph to predict the actions that the attacker may take. For example, if there is a firmware vulnerability in the router, the TTP knowledge graph will predict that the attacker may next conduct network reconnaissance, privilege escalation through this device, and ultimately attack other internal network devices. The BAS system will simulate the path for the attacker to exploit this vulnerability, evaluate the effectiveness of existing defense measures (such as firewalls, firmware upgrades), and give an "unprotected catastrophic type analysis", such as "The device has a remote code execution vulnerability and network isolation is not configured, which is a high-risk vulnerability". And, we can also achieve security protection through multi-device联动 response. For example: Early warning and patching: After predicting the vulnerability exploitation path, the system will immediately push a risk alert to the user and provide specific defense suggestions, such as "This device has a high-risk vulnerability, please immediately update the firmware". The defense strategy will also be continuously optimized: The BAS system will evaluate different defense strategies. For example, whether to immediately isolate the vulnerable device from the network or first push the patch and monitor the effect. Through this closed-loop evaluation, the system can continuously optimize the overall security strategy.
[0069] It should be noted that there is an unclear "联动" in the original text which is translated as "联动" here. It might need to be further clarified in the original context for a more accurate translation.In this embodiment, the types of attacks that the smart device may receive also include: network attacks (Network Attacks); specifically including: denial of service (DDoS): the attacker uses a botnet to initiate a large number of requests to the main control gateway or cloud service of the smart home, causing the system to crash or respond slowly; man-in-the-middle attack (MitM): the attacker establishes a connection between the user's mobile phone and the smart device, hijacks the communication data, steals privacy (such as camera video stream) or tampers with control instructions; network scanning: the attacker probes the open services and devices in the home network through port scanning to find an entry point for subsequent attacks. For the above various attack methods, we can use the following methods for protection: abnormal traffic monitoring: the system continuously monitors the data traffic in the home network. When it is found that the device or gateway has abnormally high traffic (such as a sudden influx of a large number of requests), an abnormal alarm will be immediately triggered. Optionally, the system can also force all devices to use an encryption protocol (such as TLS / SSL) for communication and perform two-way identity authentication to prevent man-in-the-middle attacks from stealing and tampering with data. Moreover, we can also achieve security protection through multi-device linkage response. For example, threat intelligence sharing: when a device or gateway encounters a DDoS attack, the system will synchronize this threat information to other devices and establish a temporary "blacklist" internally to block access from the attack source IP. Or, if the system determines that a device is suffering from a man-in-the-middle attack, it will automatically isolate the device from the core network and place it in a separate VLAN until the user solves the security problem. At the same time, the system will notify other collaborative functions that depend on this device that they are temporarily unavailable to prevent the spread of risks.
[0070] The types of attacks that intelligent devices may receive also include: Attack Propagation; specifically including: Hopping attack: An attacker breaks into a weakly secured device (such as a smart socket), and then uses it as a springboard to further attack other high-value devices (such as NAS storage, smart central control gateway) in the home network; Worm-like propagation: An infected device uses its own vulnerabilities or weak passwords to automatically scan and infect other devices of the same type in the network. For the above various attack means, we can adopt the following methods for protection. For example, Risk Propagation Model Simulation: This is the core capability of this embodiment. The system dynamically simulates the propagation path, speed, and impact of risks among different devices by constructing an industrial-grade risk propagation model. For example, if a smart socket (D1) is compromised, the model will calculate how its risk inventory is transmitted to other devices through network connections (such as connections with D2 and D3). Heatmap Visualization: The system presents the risk propagation results to the user, allowing the user to clearly see which devices are risk sources, which are "super spreaders", and which devices are in the "danger zone". Moreover, we can also achieve security protection through multi-device linkage response. For example, the system will recommend the optimal defense strategy according to the results of the risk propagation model. For example, if the model shows that the smart central control gateway is a key node for risk propagation, the system will recommend strengthening this device first, and even in some cases, recommend temporarily disconnecting its connection with high-risk devices. Closed-loop Negative Feedback: When the system takes defense measures (such as network isolation of the attacked device), the risk propagation model will run again to evaluate whether this measure effectively inhibits the spread of risks. If it is effective, the system will record it as a successful negative feedback loop and optimize future defense strategies; if it is ineffective, the strategy will continue to be adjusted until the risk is controlled.
[0071] Step S3: Intuitively present the comparison result and the security risk status in the form of a heatmap to display the risk distribution and intensity of devices or areas, and integrate the analysis of unprotected disaster types predicted by TTP and the protection effect diagram based on the ATT&CK framework.
[0072] This step aims to intuitively present the analysis results and the security risk status of the first two stages (digitization of device behavior chains and logicalization of scenarios) in the form of a heatmap to display the risk distribution and intensity of devices or areas. This can help users or managers quickly understand which parts of the system are at risk or abnormal, so as to quickly locate high-risk areas and assist users in taking response measures. In the field of smart home where users may not have professional IT knowledge, this kind of visualization is particularly important. Implementation details and integration with TTP prediction: The system will identify the risk levels and distributions on the heatmap through different colors or intensities (such as red for high risk and green for safe). More importantly, this method integrates the TTP prediction ability into risk visualization to provide deeper insights and quantitative verification.
[0073] The BAS (Breach and Attack Simulation) assessment system can generate a "Top 5 Analysis of Unprotected Attack Types" by simulating actual attacks. This identifies the most frequently bypassed or unprotected attack types in smart homes (e.g., weak password attacks on specific IoT devices, firmware vulnerability exploits, etc.) and quantifies their degree of unprotection.
[0074] Implementation: The "red areas" on the heatmap not only represent predicted risks but also empirically verified weaknesses. The system can dynamically adjust the color depth or flashing frequency of devices on the heatmap to highlight devices or areas associated with these "unprotected high-risk types." For example, if a smart door lock (D1) is listed as an "unprotected high-risk type" due to a firmware vulnerability, even if its risk level has not yet reached its maximum, the heatmap will highlight its potential, verified vulnerability with special markers (such as bold borders or specific icons). The "ATT&CK Framework-Based Protection Effect Illustration" provided by the BAS system can meticulously present the specific defense capabilities of smart home systems at different attack phases (such as initial access, persistence, and lateral movement). This adds a deeper professional dimension to risk visualization. The heatmap can be designed to be interactive; when a user clicks on a device or area, a detailed information box pops up containing the protection effect of that device / area at different tactical phases of the ATT&CK framework (e.g., "Initial Access" protection rate: 80%). Furthermore, the industrial-grade risk transmission model is a key innovation of this invention, applied for the first time in the smart home field. It can dynamically simulate the evolution and propagation of security risks in smart device networks. This model utilizes stock, traffic, auxiliary variables, and feedback loops to describe the security risk status of smart devices. The introduction of a TTP knowledge graph and predictive capabilities significantly enhances the model's predictive accuracy, parameter calibration capabilities, and intelligent guidance for defense strategies. Core model concepts: Stocks: Represents the "Risk Level" or "Vulnerability Count" of each smart device. For example, a device's "cumulative risk stock" may increase due to the discovery of new vulnerabilities or decrease due to patching.
[0075] Flows: Represent the rate at which a stock changes over time; it can be the "Risk Increase Rate" or the "Risk Propagation Rate." For example, after a device is attacked, its risk will flow to other devices in the network at a certain rate.
[0076] Auxiliary variables: These are the determinants of traffic, including the device's "current risk level," "network connectivity strength," and "vulnerability of neighboring devices."
[0077] Feedback loops describe the mutual influence between variables.
[0078] Positive feedback: A loop that amplifies risk. For example, if device A is infected and attacks device B, the increased risk on device B, in turn, encourages attacks on device C, accelerating the spread of risk throughout the system.
[0079] Negative feedback: A loop that mitigates risk. For example, when a monitoring system detects an anomaly, it initiates isolation or repair mechanisms to reduce equipment risk and suppress further spread.
[0080] Mathematical Models and Formulas: Industrial-grade risk transmission models typically use difference equations to simulate changes in the stock of risk for each device.
[0081] in: External targeting equipment Threats such as new vulnerability discoveries or direct attacks.
[0082] Risk outflow rate ( (): Mainly from defensive measures and risk reduction.
[0083]
[0084] in: : Defense and attenuation rate constant, reflecting the efficiency of risk reduction.
[0085] :equipment The defense strength (0 or 1, where 0 means no defense and 1 means that defense measures such as isolation or patching have been activated).
[0086] A dynamic simulation example integrating a TTP knowledge graph: Assume a smart home system includes the following core smart devices: D1: Smart door lock, D2: Smart camera, D3: Smart lighting system, D4: Smart central control gateway. TTP knowledge graph enhancement mechanism: The TTP prediction scheme predicts network attack behavior by combining a Large Language Model (LLM) TTP knowledge graph. The TTP knowledge graph extracts TTP entities (such as attack techniques and vulnerabilities) and their causal relationships from unstructured data such as security reports.
[0087] TTP knowledge graph construction: Data input: Collect security logs of smart home systems (such as gateway alarms and sensor data) and penetration test reports.
[0088] Entity Extraction and Relation Extraction: Utilizing pre-trained models and large language models (such as Grok3), extract TTP entities (e.g., "unauthorized unlocking of door locks," "unauthorized firmware access," "unauthorized data transmission") and other entities (e.g., vulnerabilities, malware families) and extract their causal relationships (e.g., "unauthorized unlocking"). (Camera control).
[0089] Graph Update: Subgraphs are merged into the TTP knowledge graph through entity alignment and triple fusion.
[0090] External threat intrusion (TTP-driven): Scenario: Simulate an external attack on a smart door lock (D1).
[0091] TTP Enhancement: The TTP prediction scheme identifies alarm data related to D1 (such as abnormal unlocking attempts or unauthorized firmware access to the smart lock) and maps it to TTP entities in the TTP knowledge graph. Based on the TTP prediction results, the system sets ExternalThreats1(Δt) to a non-zero value (e.g., 50), making... The number of vulnerabilities is increasing rapidly. Simultaneously, the TTP knowledge graph may identify specific vulnerabilities in D1 and use "unauthorized firmware access" as the initial TTP, impacting the existing risk inventory of D1.
[0092] Risk begins to spread (TTP enhancement): D1 to D4 (Gateway): Risk Inventory of Smart Lock (D1) After being added, it will connect to the central control gateway (D4) and use Flow14(t)=α S1(t) C14 The rate propagates from V4 to D4. The TTP prediction scheme provides a causal chain of attack paths, such as, "unauthorized firmware access to D1..." Using D1 as a springboard for network reconnaissance D4. If TTP predicts that D4 is vulnerable to such reconnaissance, then D4's inherent vulnerability... and risk accumulation It will accelerate.
[0093] D4 propagates to D2 (camera) and D3 (lighting): Once the risk of D4... Reach a certain level (e.g.) This could become a new source of risk. TTP prediction schemes can provide a higher probability of subsequent attack paths; for example, if a TTP predicts a "privilege escalation" TTP on D4, it may subsequently predict (D2) or (D3).
[0094] Positive feedback loop enhancement: If the smart camera (D2) is highly vulnerable (high (e.g., 0.8) and was quickly compromised ( (Additionally), attackers could use D2 as a springboard to further attack other devices (such as D3), or even gain deeper control over D1. The causal chains of the TTP knowledge graph clarify the connections between these attacks, making the simulation of positive feedback loops more accurate and concrete, and accelerating the spread of risk throughout the system.
[0095] System Monitoring and Defense (TTP Guide): Anomaly identification and scene comparison: The "digitalization of device behavior chain" stage monitors the fine-grained operation of devices in real time, forming "anomaly sequences". For example, when the system detects unauthorized data transmission from the smart camera (D2), the TTP prediction scheme will map it to the "data theft" TTP in the knowledge graph.
[0096] Security Risk Assessment: During the "Scene Logicization" phase, these "abnormal sequences" are compared with preset "expected paths" (e.g., the camera should not transmit data in "away mode"). If behavior deviates from expectations, the TTP-predicted causal chain (e.g., "unauthorized data transmission") is analyzed. The "data breach" will serve as an important basis for determining whether the abnormal sequence constitutes a security risk and its severity.
[0097] Defense Triggering and TTP Guidance: When a security risk is detected, the system triggers defensive measures. The high-ranking causal chain output by the TTP prediction scheme provides intelligent guidance for these defensive measures. For example, at a certain point in time... The system will: TTP predictions recommend network isolation for the D1 smart lock (disconnecting its network connection to prevent further spread).
[0098] TTP predicts and recommends pushing emergency patches to the D2 smart camera (e.g., for a predicted data theft vulnerability).
[0099] At this point, the risk outflow rate is out, and i(t) = β. Si(t) The Di(t) formula begins to take effect because When the value becomes 1, the risk outflow rate increases, and the stock of equipment risk begins to decrease.
[0100] Risk mitigation and system recovery (TTP validation and negative feedback): As defensive measures are activated, the risk reserves of D1 and D2 will gradually decrease.
[0101] Negative feedback loop verification: Reducing risks D1 and D2 decreases the traffic they propagate to other devices. Simultaneously, the BAS system can simulate whether the attack is truly suppressed after defensive measures (such as isolation or patching). If the BAS simulation results show that the defensive measures are effective, the actual effect of the negative feedback loop is verified. If ineffective, the TTP prediction model adjusts the causal chain parameters to further optimize the defense strategy.
[0102] The overall risk level of the system will tend to stabilize or decrease, thus effectively containing the risks.
[0103] Model Application and Interpretation: Through the dynamic simulation of the TTP knowledge graph integrated above, the smart home system can: predict risk propagation paths: clearly see how an attack starts from the smart door lock, first affects the gateway, and then spreads to the camera and lighting system, and these paths are enhanced and verified by the causal chains of the TTP knowledge graph.
[0104] Evaluate the effectiveness of defense strategies: Compare the impact of different defense measures (such as isolation and patching under TTP guidance) on suppressing the spread of risk, thereby optimizing the response mechanism.
[0105] Identify system vulnerabilities: Identify highly connected or vulnerable devices such as the smart central control gateway (D4) and smart cameras (D2) as "critical nodes" or "super-spreaders," and prioritize hardening these devices. The "unprotected disaster types" predicted by TTP and the protection effect diagrams of the ATT&CK framework can further highlight these vulnerabilities.
[0106] Visualized dynamic evolution: The risk inventory of each device is plotted as a curve over time. Combined with risk visualization (heat map), it intuitively shows the accumulation, outbreak and decay of risks on the smart home floor plan. It also integrates attack paths and causal relationships predicted by TTP, making it easy for users or managers to quickly understand and respond.
[0107] This method compares the actual observed device behavior sequences with the pre-set expected logical paths of the scenario, and draws on the rigor of industrial-grade risk transmission models, as well as the intelligence of TTP knowledge graphs and predictions, to achieve a deep understanding and prediction of the security status of smart home systems, leaping from passive response "single-point alarms" to proactive prevention and system resilience "system immunity".
[0108] In this embodiment, BAS further implements auxiliary variables in the calibration risk transmission model, such as the inherent vulnerability of calibration equipment. Inherent vulnerability of equipment in risk transmission models Parameters can be obtained or updated based on the actual attack effects simulated by the BAS system. For example, if the BAS simulation attempts to exploit a vulnerability in a smart camera (D2) and successfully compromises it (i.e., the vulnerability is successfully exploited), the Vi value of D2 can be increased. Conversely, if multiple attempts fail, it may indicate that the vulnerability has a minor impact or has been patched, and adjustments can be made accordingly. These calibrations will also be synchronized with vulnerability information in the TTP knowledge graph.
[0109] Calibrate network connection strength ( The risk propagation rate constant (α) can be used for calibration when there is a discrepancy between model predictions and BAS measured results. And α. For example, if the model predicts that the risk propagation from D1 to D4 will be rapid, but BAS simulations show that the propagation speed is much lower than expected due to network configuration or other reasons, then the corresponding adjustments can be made. The value (reflecting the tightness of network connectivity from D1 to D4) or the risk propagation rate constant α (reflecting the efficiency of risk diffusion) is used. These calibration processes also refer to the relationships between devices and attack propagation characteristics in the TTP knowledge graph.
[0110] Updated External Threats (ExternalThreatsi(t)): The BAS system can simulate external threats to the device (such as new vulnerability discoveries or direct attacks). The results of these simulations can be directly used as input to the ExternalThreatsi(t) parameters, enabling the model to more realistically reflect the impact of external threats.
[0111] Based on multi-dimensional analysis results (including attack success rate, analysis of unprotected types, and the protection effect of the ATT&CK framework), the BAS system can automatically generate actionable security improvement guidance and suggestions.
[0112] These suggestions can be directly translated into an assessment of "defense strength" in system dynamics models. The system can provide optimization suggestions, such as when BAS indicates that a smart camera has a high-risk vulnerability that has been successfully exploited, it can recommend an immediate firmware update (adding...). ), or isolate the device (change) When BAS points out that improper IP blocking configuration has led to attacks bypassing it, the system will provide suggestions for adjusting the configuration. This transforms "risk identification" into practical "risk mitigation," greatly improving the efficiency and resilience of "system immunity."
[0113] The comparison results and security risk status are presented visually in the form of a heatmap to show the risk distribution and intensity of equipment or areas. This helps users or managers quickly understand which parts of the system are at risk or abnormal, thereby quickly locating high-risk areas and assisting users in taking countermeasures.
[0114] It can also integrate the analysis of unprotected major disaster types generated by TTP prediction with the protection effect diagram based on the ATT&CK framework. Analysis of Unprotected Severe Attack Types: The BAS system can simulate actual attacks to generate a "Top 5 Analysis of Unprotected Severe Attack Types," identifying the most frequently bypassed or unprotected attack types in smart homes (e.g., weak password attacks on specific IoT devices, firmware vulnerability exploits, etc.) and quantifying their degree of unprotection. This information is overlaid on a heatmap, making the "red areas" not only predicted risks but also empirically verified weak points, thereby improving the accuracy and guidance of visualization.
[0115] A Protection Effectiveness Illustration Table Based on the ATT&CK Framework: BAS assessment results can be presented as a "Protection Effectiveness Illustration Table Based on the ATT&CK Framework". This table can provide a detailed presentation of the specific defense capabilities of smart home systems at different attack stages (such as initial access, persistence, and lateral movement), and integrate this information into a risk heatmap, adding a deeper professional dimension to risk visualization.
[0116] Through the above simulation, this method can achieve the following objectives: Predicting risk propagation paths: Clearly see how an attack starts from a smart lock, first affecting the gateway, and then spreading to cameras and lighting systems. Combined with TTP's predicted attack paths and causal relationships, it provides more detailed and forward-looking predictions.
[0117] Evaluate the effectiveness of defense strategies: compare the impact of different time points or different defense measures (such as early isolation and immediate patching) on suppressing the spread of risk, thereby optimizing the response mechanism and optimizing defense measures based on TTP predictions and BAS recommendations.
[0118] Identifying System Vulnerabilities: Through the model, highly connected or vulnerable devices such as the smart central control gateway (D4) and smart cameras (D2) can be identified as "critical nodes" or "super-spreaders," allowing for priority hardening of these devices. The TTP knowledge graph will provide the specific vulnerabilities and attack methods of these "super-spreaders."
[0119] Visualized dynamic evolution: The risk inventory of each device is plotted as a curve over time, and even combined with "risk visualization (heat map)" to intuitively show the accumulation, outbreak and decay of risks on the smart home floor plan, so that users or managers can quickly understand and respond. It also integrates the analysis of unprotected major disaster types and the protection effect diagram of the ATT&CK framework to provide a more comprehensive risk view.
[0120] This example demonstrates how a system dynamics model can dynamically simulate the evolution and propagation of security risks in smart homes through the interaction of stock, flow, auxiliary variables, and feedback loops, and by deeply integrating the causal relationships of the TTP knowledge graph and the attack paths predicted by TTP, as well as the empirical verification and calibration capabilities of the BAS system, thereby achieving a qualitative leap from "single point alarm" to "system immunity".
[0121] This invention also proposes a multi-dimensional dynamic monitoring and early warning system for smart device security, such as... Figure 2 As shown, the system includes: The Device Behavior Chain Digitization Module continuously monitors all operations and status changes of smart devices in real time, digitizing their behavior into device behavior sequences and identifying anomalous sequences that deviate from the normal behavior patterns of smart devices. These anomalous sequences can be used as input for subsequent Time-to-Patient (TTP) prediction. The core of this module is the system's continuous real-time monitoring of the operations and status changes of all smart devices in the smart home, digitizing them into device behavior sequences, and identifying anomalous sequences that deviate from the normal behavior patterns of smart devices. This is equivalent to real-time monitoring and pattern recognition of the actual, fine-grained device operations and status changes occurring in the smart home system. This step specifically includes: Data Acquisition: The system continuously collects sensor data and environmental parameters from smart devices, such as the on / off status of smart door locks, recording commands from smart cameras, and brightness adjustment records from smart lighting systems. This data constitutes the original "sequence" of device behavior. Anomaly Identification: By performing pattern recognition on these digitized sequences, potential security risks are quickly identified, such as unauthorized operations, abnormal status changes, or signs of device malfunction.
[0122] Example: When the smart door lock (D1) makes an abnormal unlocking attempt (such as multiple incorrect fingerprint recognitions within a short period of time) or unauthorized firmware access; or when the smart camera (D2) transmits data without authorization (such as uploading video to an external IP address in away mode); or when the smart lighting system (D3) experiences abnormal light changes. The system will identify these as "abnormal sequences". In this embodiment, at this stage, the "risk stock" of each device ( The threshold will increase based on the severity and frequency of the detected anomalous sequences. For example, after a smart lock identifies multiple anomalous attempts, The value will increase rapidly. The "abnormal sequences" identified in this step can be directly used as input data for subsequent TTP prediction schemes (combining large language models and TTP knowledge graphs). For example, the BAS system simulates attacks to generate alarm data, and this alarm data (i.e., abnormal sequences) is mapped to TTP entities in the knowledge graph, thereby initiating the prediction of potential attack paths. This transforms security monitoring from passive alerting to proactive predictive defense.
[0123] The scene logicization module is used to transform the preset smart home scene logic into expected path models that can be used for security analysis, compare them with the abnormal sequences, and combine the causal chain of the TTP knowledge graph to determine whether the abnormal sequences constitute a security risk. This module aims to transform the preset scene function schemes in smart homes into "expected path" models that can be used for security analysis. These "expected paths" represent the expected and normal linkage relationships and operating procedures between devices in a specific scenario. The system compares the "abnormal sequences" (i.e., actual device behaviors that may deviate from normal behavior) identified in the previous stage with these "expected path" models to determine whether the abnormal sequences constitute a security risk. In this embodiment, it specifically includes: Expected Path Modeling: Various "scene-based functionalities" meticulously planned in smart home solutions, such as "Home Mode," "Away Mode," or "Sleep Mode," can all be considered potential "expected paths." These paths define "what should happen" and "how it should happen" in specific scenarios. For example, the expected path for "Home Mode": When the smart door lock (D1) is unlocked from the outside, the expected triggering actions include: automatically turning on the entryway light and living room light (curtains may open during the day); automatically turning on the air conditioner and fresh air system and adjusting them to a suitable temperature; and controlling the robot vacuum to return to the home.
[0124] The expected path of "Away Mode": When the door is closed and locked from the outside, the expected triggering actions include: automatically turning off all the lights, air conditioning, fresh air system and other equipment in the house; controlling the window opener to close the windows (as needed); and controlling the robot vacuum cleaner to start working.
[0125] The expected path of "Sleep Mode" is: automatically turn off all lights and curtains in the room, and adjust the air conditioner temperature to the preferred sleep temperature.
[0126] Comparison and risk assessment: The system will compare the "abnormal sequence" detected in the "digitalization of device behavior chain" stage (step S1) with the above "expected path" model.
[0127] For example, if, after activating "Away Mode," the system detects anomalies such as the smart camera (D2) being controlled without authorization and transmitting data, or a light (D3) not turning off as expected, this deviates from the "expected path" of "Away Mode," and the system will determine that a security risk exists. This also applies when the smart lock (D1) exhibits anomalies with multiple unauthorized unlocking attempts, while the expected path of "Home Mode" is not triggered. This comparison elevates security monitoring from merely responding to a single event (such as a gas leak alarm) to monitoring the integrity and correctness of the entire behavioral chain.
[0128] Security risks are assessed by combining the causal chains of the TTP knowledge graph: when an abnormal sequence deviates from the expected path, this deviation (i.e., abnormal behavior) can be mapped to an initial TTP entity in the TTP knowledge graph. Through the causal chains of the TTP knowledge graph, the system can predict subsequent possible attack behaviors or potential attack paths. These predictions serve as important criteria for determining whether the abnormal sequence constitutes a security risk and its severity.
[0129] Specifically, when the comparison detects an abnormal sequence of unauthorized data transmission by the smart camera (D2) in "away mode", the system will map this behavior to a certain reconnaissance or data theft TTP entity in the TTP knowledge graph.
[0130] The TTP prediction scheme will utilize the causal chain mechanism of knowledge graphs to predict potential secondary or accompanying TTPs, such as "unauthorized data transfer" leading to "privilege escalation" or "data breach".
[0131] These predicted subsequent TTPs will significantly improve the system's risk assessment and severity evaluation of initial anomalous behavior. For example, if a data breach is predicted, the anomalous sequence constitutes a high-level security risk.
[0132] At this stage, when a security risk is identified through logical comparison of the scenario, the system will trigger defensive measures. For example, when an external attack risk is detected in the smart door lock (D1), its risk inventory... It will rise, and through its network connection strength with the intelligent central control gateway (D4) ) and the vulnerability of the gateway itself ( ), based on risk transmission rate The rate flows to D4. Once the risk stock in D4... Once it reaches a certain level, it will spread to other devices (such as D2 and D3) as a new source of risk.
[0133] Example of a positive feedback loop: If the smart camera (D2) is highly vulnerable (high... ) and was quickly invaded ( (Increase) An attacker could use D2 as a springboard to further attack other devices (such as D3), or even gain deeper control over D1, which would form a positive feedback loop and accelerate the spread of risk throughout the system.
[0134] Defense Triggering and Risk Outflow: Once a risk is identified and determined to be a security risk, the system will trigger defensive measures. For example, at a certain point in time... The system will assess the defense strength of high-risk devices (such as D1 and D2). It changes from 0 to 1. At this point, the risk outflow rate... It began to take effect, because As the threshold changes to 1, the risk outflow rate increases, and the stock of device risks begins to decrease. This step compares actual device behavior (abnormal sequences) with preset normal operating logic (expected paths) and performs in-depth analysis using the causal chain of the TTP knowledge graph. This not only identifies individual device anomalies but also assesses their severity based on scenario logic and predicts potential attack development, thereby improving the accuracy and severity of early warnings. It elevates the understanding from "knowing that a device has a problem" to "knowing that the execution logic of a scenario has a problem" and can predict the subsequent development path of an attack. This is a crucial step in the qualitative leap of smart home security from "single-point alarm" to "system immunity."
[0135] In this embodiment, the types of attacks that the smart device may receive include: brute force cracking, that is, the attacker makes a large number of password or fingerprint attempts on the smart door lock or camera within a short period of time; abnormal access: the smart camera is suddenly remotely activated during non-working hours at night, or the smart speaker is abnormally awakened when the user does not issue an instruction; malicious control: the smart curtain or lighting system receives frequent and irregular switch commands. For the above various attack means, we can adopt the following methods for protection: Real-time behavior sequence analysis: The system continuously collects the "behavior sequence" of device operations. For example, in the "away mode", after the door closing instruction of the smart door lock, the system expects the curtain to close and the lights to go out. If the door lock receives multiple fingerprint error instructions immediately after closing the door, the system will mark it as an abnormal sequence. Scenario logic comparison: The system compares this abnormal sequence with the preset expected path models such as the "away mode". If it is found that it does not match the normal logic, for example, frequent attempts occur on the door lock in the "away mode", the system will immediately determine it as a potential risk and predict subsequent attacks in combination with the TTP knowledge graph. Moreover, we can also achieve security protection through multi-device linkage response. For example, when the smart door lock detects multiple brute force cracking attempts, it will not only alarm itself but also send an alarm to the main control gateway. The gateway will cooperate with other devices, such as: Smart camera: Immediately start recording and aim at the door lock area. Smart lighting system: Adjust the lights in the entrance area to high brightness and flash to deter potential attackers. The smart speaker issues a warning, such as "Please stop the operation immediately". Risk conduction model: When the door lock is attacked, the risk conduction model will analyze whether this risk will spread to other devices through the home network. For example, if there is a high-risk connection between the door lock and the central control gateway, the system will predict that the risk stock of the central control gateway will increase and remind the user to strengthen the security measures of the central control gateway.
[0136] In this embodiment, the types of attacks that the smart device may receive also include vulnerability exploitation. For example, firmware vulnerabilities: attackers use known firmware vulnerabilities of smart routers (such as CVE-2023-XXXX) to remotely obtain administrator privileges; weak passwords / default passwords: attackers enter the device by scanning and exploiting the default weak passwords of smart cameras or smart sockets (such as "admin / 123456"). SQL injection: attackers use the Web interface vulnerabilities of the smart home control App to steal user data or tamper with device control instructions. For the above various attack methods, we can adopt the following methods for protection: TTP knowledge graph prediction: When it is found that a certain device (such as a router) has a known vulnerability, the system will use the causal chain of the TTP knowledge graph to predict the actions that the attacker may take. For example, if there is a firmware vulnerability in the router, the TTP knowledge graph will predict that the attacker may then conduct network reconnaissance, privilege escalation through this device, and ultimately attack other internal network devices. The BAS system will simulate the path for the attacker to exploit this vulnerability, evaluate the effectiveness of existing defense measures (such as firewalls, firmware upgrades), and give an "unprotected disaster type analysis", such as "The device has a remote code execution vulnerability and network isolation is not configured, which is a high-risk vulnerability". Also, we can achieve security protection through multi-device联动 response. For example: Early warning and patching: After the system predicts the vulnerability exploitation path, it will immediately push a risk alert to the user and provide specific defense suggestions, such as "This device has a high-risk vulnerability, please immediately update the firmware". The defense strategy will also be continuously optimized: The BAS system will evaluate different defense strategies. For example, whether to immediately isolate the vulnerable device from the network or first push patches and monitor the effects. Through this closed-loop evaluation, the system can continuously optimize the overall security strategy.
[0137] It should be noted that the term "联动" in the original text may not be accurately translated as "联动" in the English text. It might be a specific technical term in the relevant field. If there is a more appropriate translation for this term, it needs to be adjusted according to the actual situation. Here, a literal translation is provided first for the purpose of meeting the translation requirements.In this embodiment, the types of attacks that the smart device may receive also include: network attacks (Network Attacks); specifically including: Denial of Service (DDoS): The attacker uses a botnet to initiate a large number of requests to the main control gateway or cloud service of the smart home, causing the system to crash or respond slowly; Man-in-the-Middle (MitM) attack: The attacker establishes a connection between the user's mobile phone and the smart device, hijacks the communication data, steals privacy (such as camera video streams) or tampers with control instructions; Network scanning: The attacker probes the open services and devices in the home network through port scanning to find an entry for subsequent attacks. For the above various attack means, we can adopt the following methods for protection: Abnormal traffic monitoring: The system monitors the data traffic in the home network in real time. When an abnormally high traffic (such as a sudden influx of a large number of requests) is found in the device or gateway, an abnormal alarm will be immediately triggered. Optionally, the system can also force all device-to-device communications to use encryption protocols (such as TLS / SSL) and perform two-way identity authentication to prevent MitM attacks from stealing and tampering with data. Also, we can achieve security protection through multi-device联动 response. For example, threat intelligence sharing: When a device or gateway encounters a DDoS attack, the system will synchronize this threat information to other devices and establish a temporary "blacklist" internally to block access from the attack source IP. Or, if the system determines that a device is suffering from a MitM attack, it will automatically isolate the device from the core network and place it in a separate VLAN until the user solves the security problem. At the same time, the system will notify other collaborative functions that depend on this device that they are temporarily unavailable to prevent the spread of risks.
[0138] It should be noted that there is a character "联动" in the original text which may be a misspelling or an incorrect term. I translated it as "联动" as it is, but it might need to be corrected in the original context.The types of attacks that smart devices may receive also include: Attack Propagation; specifically including: Jump - point attack: An attacker breaks into a weakly - secured device (such as a smart socket), and then uses it as a springboard to further attack other high - value devices in the home network (such as NAS storage, smart central control gateway); Worm - like propagation: An infected device uses its own vulnerabilities or weak passwords to automatically scan and infect other devices of the same type in the network. For the above - mentioned various attack methods, we can adopt the following methods for protection. For example, Risk Propagation Model Simulation: This is the core capability of this embodiment. The system constructs an industrial - level risk propagation model to dynamically simulate the propagation path, speed, and impact of risks among different devices. For example, if the smart socket (D1) is compromised, the model will calculate how its risk inventory is transmitted to other devices through network connections (such as connections with D2 and D3). Heat - map Visualization: The system presents the risk propagation results to the user, allowing the user to clearly see which devices are risk sources, which are "super - spreaders", and which devices are in the "danger zone". And, we can also achieve security protection through multi - device联动 response. For example, the system will recommend the optimal defense strategy based on the results of the risk propagation model. For example, if the model shows that the smart central control gateway is a key node for risk propagation, the system will recommend strengthening this device first, and even in some cases, recommend temporarily disconnecting its connection with high - risk devices. Closed - loop Negative Feedback: When the system takes defense measures (such as network isolation of the attacked device), the risk propagation model will run again to evaluate whether this measure effectively inhibits the spread of risks. If it is effective, the system will record it as a successful negative - feedback loop and optimize future defense strategies; if it is ineffective, it will continue to adjust the strategy until the risk is controlled.
[0139] A risk visualization module, which is used to intuitively present the comparison result and the security risk status in the form of a heat - map, so as to display the risk distribution and intensity of devices or regions, and can integrate the analysis of unprotected disaster - prone types predicted by TTP and the protection effect diagram based on the ATT&CK framework; and in this module, a risk propagation model enhanced by the TTP knowledge graph dynamically simulates the evolution and propagation process of the security risk in the smart device network, and integrates the attack path and causal relationship predicted by TTP.
[0140] This module aims to visually present the analysis results and security risk status of the first two stages (digitalization of device behavior chains and logicalization of scenarios) in the form of a heatmap, showcasing the risk distribution and intensity of devices or areas. This helps users or managers quickly understand which parts of the system are at risk or abnormal, thereby quickly locating high-risk areas and assisting users in taking countermeasures. This visualization is particularly important in fields like smart homes where users may lack specialized IT knowledge. Implementation details and TTP prediction integration: The system uses different colors or intensities (e.g., red for high risk, green for safe) to identify the risk level and distribution on the heatmap. More importantly, this module integrates TTP prediction capabilities into risk visualization to provide deeper insights and quantitative verification.
[0141] The BAS (Breach and Attack Simulation) assessment system can generate a "Top 5 Analysis of Unprotected Attack Types" by simulating actual attacks. This identifies the most frequently bypassed or unprotected attack types in smart homes (e.g., weak password attacks on specific IoT devices, firmware vulnerability exploits, etc.) and quantifies their degree of unprotection.
[0142] Implementation: The "red areas" on the heatmap not only represent predicted risks but also empirically verified weaknesses. The system can dynamically adjust the color depth or flashing frequency of devices on the heatmap to highlight devices or areas associated with these "unprotected high-risk types." For example, if a smart door lock (D1) is listed as an "unprotected high-risk type" due to a firmware vulnerability, even if its risk level has not yet reached its maximum, the heatmap will highlight its potential, verified vulnerability with special markers (such as bold borders or specific icons). The "ATT&CK Framework-Based Protection Effect Illustration" provided by the BAS system can meticulously present the specific defense capabilities of smart home systems at different attack phases (such as initial access, persistence, and lateral movement). This adds a deeper professional dimension to risk visualization. The heatmap can be designed to be interactive; when a user clicks on a device or area, a detailed information box pops up containing the protection effect of that device / area at different tactical phases of the ATT&CK framework (e.g., "Initial Access" protection rate: 80%). Furthermore, the industrial-grade risk transmission model is a key innovation of this module, applied for the first time in the smart home field. It can dynamically simulate the evolution and propagation of security risks in smart device networks. This model utilizes stock, traffic, auxiliary variables, and feedback loops to describe the security risk status of smart devices. The introduction of a TTP knowledge graph and predictive capabilities greatly enhances the model's predictive accuracy, parameter calibration capabilities, and intelligent guidance for defense strategies. Core model concepts: Stocks: Represents the "Risk Level" or "Vulnerability Count" of each smart device. For example, a device's "cumulative risk stock" may increase due to the discovery of new vulnerabilities or decrease due to patching.
[0143] Flows: Represent the rate at which a stock changes over time; it can be the "Risk Increase Rate" or the "Risk Propagation Rate." For example, after a device is attacked, its risk will flow to other devices in the network at a certain rate.
[0144] Auxiliary variables: These are the determinants of traffic, including the device's "current risk level," "network connectivity strength," and "vulnerability of neighboring devices."
[0145] Feedback loops describe the mutual influence between variables.
[0146] Positive feedback: A loop that amplifies risk. For example, if device A is infected and attacks device B, the increased risk on device B, in turn, encourages attacks on device C, accelerating the spread of risk throughout the system.
[0147] Negative feedback: A loop that mitigates risk. For example, when a monitoring system detects an anomaly, it initiates isolation or repair mechanisms to reduce equipment risk and suppress further spread.
[0148] Mathematical Models and Formulas: Industrial-grade risk transmission models typically use difference equations to simulate changes in the stock of risk for each device.
[0149] in: External targeting equipment Threats such as new vulnerability discoveries or direct attacks.
[0150] Risk outflow rate ( (): Mainly from defensive measures and risk reduction.
[0151]
[0152] in: : Defense and attenuation rate constant, reflecting the efficiency of risk reduction.
[0153] :equipment The defense strength (0 or 1, where 0 means no defense and 1 means that defense measures such as isolation or patching have been activated).
[0154] A dynamic simulation example integrating a TTP knowledge graph: Assume a smart home system includes the following core smart devices: D1: Smart door lock, D2: Smart camera, D3: Smart lighting system, D4: Smart central control gateway. TTP knowledge graph enhancement mechanism: The TTP prediction scheme predicts network attack behavior by combining a Large Language Model (LLM) TTP knowledge graph. The TTP knowledge graph extracts TTP entities (such as attack techniques and vulnerabilities) and their causal relationships from unstructured data such as security reports.
[0155] TTP knowledge graph construction: Data input: Collect security logs of smart home systems (such as gateway alarms and sensor data) and penetration test reports.
[0156] Entity Extraction and Relation Extraction: Utilizing pre-trained models and large language models (such as Grok3), extract TTP entities (e.g., "unauthorized unlocking of door locks," "unauthorized firmware access," "unauthorized data transmission") and other entities (e.g., vulnerabilities, malware families) and extract their causal relationships (e.g., "unauthorized unlocking"). (Camera control).
[0157] Graph Update: Subgraphs are merged into the TTP knowledge graph through entity alignment and triple fusion.
[0158] External threat intrusion (TTP-driven): Scenario: Simulate an external attack on a smart door lock (D1).
[0159] TTP Enhancement: The TTP prediction scheme identifies alarm data related to D1 (such as abnormal unlocking attempts or unauthorized firmware access to the smart lock) and maps it to TTP entities in the TTP knowledge graph. Based on the TTP prediction results, the system sets ExternalThreats1(Δt) to a non-zero value (e.g., 50), making... The number of vulnerabilities is increasing rapidly. Simultaneously, the TTP knowledge graph may identify specific vulnerabilities in D1 and use "unauthorized firmware access" as the initial TTP, impacting the existing risk inventory of D1.
[0160] Risk begins to spread (TTP enhancement): D1 to D4 (Gateway): Risk Inventory of Smart Lock (D1) After being added, it will connect to the central control gateway (D4) and use Flow14(t)=α S1(t) C14 The rate propagates from V4 to D4. The TTP prediction scheme provides a causal chain of attack paths, such as, "unauthorized firmware access to D1..." Using D1 as a springboard for network reconnaissance D4. If TTP predicts that D4 is vulnerable to such reconnaissance, then D4's inherent vulnerability... and risk accumulation It will accelerate.
[0161] D4 propagates to D2 (camera) and D3 (lighting): Once the risk of D4... Reach a certain level (e.g.) This could become a new source of risk. TTP prediction schemes can provide a higher probability of subsequent attack paths; for example, if a TTP predicts a "privilege escalation" TTP on D4, it may subsequently predict (D2) or (D3).
[0162] Positive feedback loop enhancement: If the smart camera (D2) is highly vulnerable (high (e.g., 0.8) and was quickly compromised ( (Additionally), attackers could use D2 as a springboard to further attack other devices (such as D3), or even gain deeper control over D1. The causal chains of the TTP knowledge graph clarify the connections between these attacks, making the simulation of positive feedback loops more accurate and concrete, and accelerating the spread of risk throughout the system.
[0163] System Monitoring and Defense (TTP Guide): Anomaly identification and scene comparison: The "digitalization of device behavior chain" stage monitors the fine-grained operation of devices in real time, forming "anomaly sequences". For example, when the system detects unauthorized data transmission from the smart camera (D2), the TTP prediction scheme will map it to the "data theft" TTP in the knowledge graph.
[0164] Security Risk Assessment: During the "Scene Logicization" phase, these "abnormal sequences" are compared with preset "expected paths" (e.g., the camera should not transmit data in "away mode"). If behavior deviates from expectations, the TTP-predicted causal chain (e.g., "unauthorized data transmission") is analyzed. The "data breach" will serve as an important basis for determining whether the abnormal sequence constitutes a security risk and its severity.
[0165] Defense Triggering and TTP Guidance: When a security risk is detected, the system triggers defensive measures. The high-ranking causal chain output by the TTP prediction scheme provides intelligent guidance for these defensive measures. For example, at a certain point in time... The system will: TTP predictions recommend network isolation for the D1 smart lock (disconnecting its network connection to prevent further spread).
[0166] TTP predicts and recommends pushing emergency patches to the D2 smart camera (e.g., for a predicted data theft vulnerability).
[0167] At this point, the risk outflow rate is out, and i(t) = β. Si(t) The Di(t) formula begins to take effect because When the value becomes 1, the risk outflow rate increases, and the stock of equipment risk begins to decrease.
[0168] Risk mitigation and system recovery (TTP validation and negative feedback): As defensive measures are activated, the risk reserves of D1 and D2 will gradually decrease.
[0169] Negative feedback loop verification: Reducing risks D1 and D2 decreases the traffic they propagate to other devices. Simultaneously, the BAS system can simulate whether the attack is truly suppressed after defensive measures (such as isolation or patching). If the BAS simulation results show that the defensive measures are effective, the actual effect of the negative feedback loop is verified. If ineffective, the TTP prediction model adjusts the causal chain parameters to further optimize the defense strategy.
[0170] The overall risk level of the system will tend to stabilize or decrease, thus effectively containing the risks.
[0171] Model Application and Interpretation: Through the dynamic simulation of the TTP knowledge graph integrated above, the smart home system can: predict risk propagation paths: clearly see how an attack starts from the smart door lock, first affects the gateway, and then spreads to the camera and lighting system, and these paths are enhanced and verified by the causal chains of the TTP knowledge graph.
[0172] Evaluate the effectiveness of defense strategies: Compare the impact of different defense measures (such as isolation and patching under TTP guidance) on suppressing the spread of risk, thereby optimizing the response mechanism.
[0173] Identify system vulnerabilities: Identify highly connected or vulnerable devices such as the smart central control gateway (D4) and smart cameras (D2) as "critical nodes" or "super-spreaders," and prioritize hardening these devices. The "unprotected disaster types" predicted by TTP and the protection effect diagrams of the ATT&CK framework can further highlight these vulnerabilities.
[0174] Visualized dynamic evolution: The risk inventory of each device is plotted as a curve over time. Combined with risk visualization (heat map), it intuitively shows the accumulation, outbreak and decay of risks on the smart home floor plan. It also integrates attack paths and causal relationships predicted by TTP, making it easy for users or managers to quickly understand and respond.
[0175] This module compares the observed device behavior sequences with the pre-defined scenario expected logic paths, and draws on the rigor of industrial-grade risk transmission models, as well as the intelligence of TTP knowledge graphs and predictions, to achieve a deep understanding and prediction of the security status of smart home systems. It leaps from passive response "single-point alarm" to proactive prevention and system resilience "system immunity".
[0176] In this embodiment, BAS further implements auxiliary variables in the calibration risk transmission model, such as the inherent vulnerability of calibration equipment. Inherent vulnerability of equipment in risk transmission models Parameters can be obtained or updated based on the actual attack effects simulated by the BAS system. For example, if the BAS simulation attempts to exploit a vulnerability in a smart camera (D2) and successfully compromises it (i.e., the vulnerability is successfully exploited), the Vi value of D2 can be increased. Conversely, if multiple attempts fail, it may indicate that the vulnerability has a minor impact or has been patched, and adjustments can be made accordingly. These calibrations will also be synchronized with vulnerability information in the TTP knowledge graph.
[0177] Calibrate network connection strength ( The risk propagation rate constant (α) can be used for calibration when there is a discrepancy between model predictions and BAS measured results. And α. For example, if the model predicts that the risk propagation from D1 to D4 will be rapid, but BAS simulations show that the propagation speed is much lower than expected due to network configuration or other reasons, then the corresponding adjustments can be made. The value (reflecting the tightness of network connectivity from D1 to D4) or the risk propagation rate constant α (reflecting the efficiency of risk diffusion) is used. These calibration processes also refer to the relationships between devices and attack propagation characteristics in the TTP knowledge graph.
[0178] Updated External Threats (ExternalThreatsi(t)): The BAS system can simulate external threats to the device (such as new vulnerability discoveries or direct attacks). The results of these simulations can be directly used as input to the ExternalThreatsi(t) parameters, enabling the model to more realistically reflect the impact of external threats.
[0179] Based on multi-dimensional analysis results (including attack success rate, analysis of unprotected types, and the protection effect of the ATT&CK framework), the BAS system can automatically generate actionable security improvement guidance and suggestions.
[0180] These suggestions can be directly translated into an assessment of "defense strength" in system dynamics models. The system can provide optimization suggestions, such as when BAS indicates that a smart camera has a high-risk vulnerability that has been successfully exploited, it can recommend an immediate firmware update (adding...). ), or isolate the device (change) When BAS points out that improper IP blocking configuration has led to attacks bypassing it, the system will provide suggestions for adjusting the configuration. This transforms "risk identification" into practical "risk mitigation," greatly improving the efficiency and resilience of "system immunity."
[0181] The comparison results and security risk status are presented visually in the form of a heatmap to show the risk distribution and intensity of equipment or areas. This helps users or managers quickly understand which parts of the system are at risk or abnormal, thereby quickly locating high-risk areas and assisting users in taking countermeasures.
[0182] It can also integrate the analysis of unprotected major disaster types generated by TTP prediction with the protection effect diagram based on the ATT&CK framework. Analysis of Unprotected Severe Attack Types: The BAS system can simulate actual attacks to generate a "Top 5 Analysis of Unprotected Severe Attack Types," identifying the most frequently bypassed or unprotected attack types in smart homes (e.g., weak password attacks on specific IoT devices, firmware vulnerability exploits, etc.) and quantifying their degree of unprotection. This information is overlaid on a heatmap, making the "red areas" not only predicted risks but also empirically verified weak points, thereby improving the accuracy and guidance of visualization.
[0183] A Protection Effectiveness Illustration Table Based on the ATT&CK Framework: BAS assessment results can be presented as a "Protection Effectiveness Illustration Table Based on the ATT&CK Framework". This table can provide a detailed presentation of the specific defense capabilities of smart home systems at different attack stages (such as initial access, persistence, and lateral movement), and integrate this information into a risk heatmap, adding a deeper professional dimension to risk visualization.
[0184] Through the above simulation, this module can achieve the following objectives: Predicting risk propagation paths: Clearly see how an attack starts from a smart lock, first affecting the gateway, and then spreading to cameras and lighting systems. Combined with TTP's predicted attack paths and causal relationships, it provides more detailed and forward-looking predictions.
[0185] Evaluate the effectiveness of defense strategies: compare the impact of different time points or different defense measures (such as early isolation and immediate patching) on suppressing the spread of risk, thereby optimizing the response mechanism and optimizing defense measures based on TTP predictions and BAS recommendations.
[0186] Identifying System Vulnerabilities: Through the model, highly connected or vulnerable devices such as the smart central control gateway (D4) and smart cameras (D2) can be identified as "critical nodes" or "super-spreaders," allowing for priority hardening of these devices. The TTP knowledge graph will provide the specific vulnerabilities and attack methods of these "super-spreaders."
[0187] Visualized dynamic evolution: The risk inventory of each device is plotted as a curve over time, and even combined with "risk visualization (heat map)" to intuitively show the accumulation, outbreak and decay of risks on the smart home floor plan, so that users or managers can quickly understand and respond. It also integrates the analysis of unprotected major disaster types and the protection effect diagram of the ATT&CK framework to provide a more comprehensive risk view.
[0188] This example demonstrates how a system dynamics model can dynamically simulate the evolution and propagation of security risks in smart homes through the interaction of stock, flow, auxiliary variables, and feedback loops, and by deeply integrating the causal relationships of the TTP knowledge graph and the attack paths predicted by TTP, as well as the empirical verification and calibration capabilities of the BAS system, thereby achieving a qualitative leap from "single point alarm" to "system immunity".
[0189] It should be understood that the processor in the embodiments of the present invention may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor described above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0190] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0191] It should be understood that the above-described memory is exemplary but not restrictive. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.
[0192] This application also provides a computer-readable storage medium for storing computer programs.
[0193] Optionally, the computer-readable storage medium can be applied to the terminal device in the embodiments of this application, and the computer program causes the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.
[0194] This application also provides a computer program product, including computer program instructions.
[0195] Optionally, the computer program product can be applied to the terminal device in the embodiments of this application, and the computer program instructions cause the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of this application. For the sake of brevity, they will not be described in detail here.
[0196] This application also provides a computer program.
[0197] Optionally, the computer program can be applied to the vehicle autonomous driving device in the embodiments of this application. When the computer program is run on a computer, it causes the computer to execute the corresponding processes implemented by the terminal device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.
[0198] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0199] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, units, and processes described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0200] In the embodiments provided in this application, it should be understood that the disclosed systems, methods, and approaches can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between systems or units may be electrical, mechanical, or other forms.
[0201] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
Claims
1. A method for multi-dimensional dynamic monitoring and early warning of smart device security, characterized in that, Includes the following steps: Continuously monitor all operations and status changes of smart devices in real time, digitize their behavior to form device behavior sequences, and identify abnormal sequences that deviate from the normal behavior patterns of smart devices. These abnormal sequences can be used as input for subsequent TTP prediction. The preset smart home scenario logic is transformed into an expected path model that can be used for security analysis, and compared with the abnormal sequence. The causal chain of the TTP knowledge graph is then used to determine whether the abnormal sequence constitutes a security risk. The comparison results and security risk status are presented intuitively in the form of a heatmap to show the risk distribution and intensity of devices or areas. It can also integrate the analysis of unprotected major disaster types generated by TTP prediction and the protection effect diagram based on the ATT&CK framework. In addition, the method uses a risk transmission model based on TTP knowledge graph enhancement to dynamically simulate the evolution and propagation process of the security risks in the smart device network, and integrates the attack paths and causal relationships predicted by TTP.
2. The method according to claim 1, wherein the risk transmission model uses risk stock, risk flow, auxiliary variables and feedback loops to describe the security risk status of the smart device, and dynamically simulates the evolution and propagation process of the security risk in the smart device network; the risk stock represents the risk level or number of vulnerabilities of each smart device; the risk flow represents the risk increase rate or risk propagation rate; the auxiliary variables represent the determinants of the flow, including the current risk level of the device, the network connection strength based on TTP association analysis and the vulnerability of neighboring devices updated by the TTP knowledge graph.
3. The method according to claim 2, wherein the feedback loop includes a positive feedback loop and a negative feedback loop, wherein the positive feedback loop is used to amplify the risk and can work in conjunction with the potential attack paths predicted by TTP to provide early warning of system-level risks; and the negative feedback loop is used to suppress the risk and can provide precise intervention targets and guidance based on the TTP prediction results.
4. The method according to claim 1, wherein, The steps for digitizing device behavior to form a device behavior sequence include: continuously collecting sensor data and environmental parameters of the smart device, and performing real-time monitoring and pattern recognition on the actual fine-grained device operations and state changes to form the anomaly sequence; the anomaly sequence is mapped to TTP entities and used as input for TTP prediction.
5. The method according to claim 1, wherein, The step of transforming the preset smart home scene logic into an expected path model that can be used for security analysis includes: taking the preset scene function scheme in the smart home as the expected path model, where the expected path represents the expected normal linkage relationship and operation process between devices in a specific scene; comparing whether the linkage relationship and operation process of the abnormal sequence are consistent with the expected path, and combining the causal chain analysis of the TTP knowledge graph to predict subsequent attack behaviors, so as to determine whether there are problems with the execution logic of the scene.
6. The method according to claim 1, wherein, The risk transmission model uses difference equations. To simulate the changes in the risk inventory of each device; among which, For equipment In time The existing risk, This refers to the simulation time step. The parameters of the model and the dynamic simulation process can be enhanced and calibrated using the TTP knowledge graph and prediction results.
7. The method according to claim 4, wherein, The risk inflow rate ,and ;in, Let the risk propagation rate be a constant. For equipment arrive Network connection strength, For devices updated based on TTP knowledge graph and vulnerability information The inherent vulnerability, For external devices The threat; the risk outflow rate ;in, For defense and attenuation rate constants, External targeted devices simulated or identified by the TTP prediction scheme The threat.
8. The method according to claim 7, wherein, When the scenario logic comparison determines that there is a security risk, the system triggers defensive measures and suppresses the further spread of the risk in the entire smart device network; the triggering and content of the defensive measures can be optimized and adjusted based on the TTP prediction results and the security improvement guidance suggestions provided by the BAS system.
9. The method according to claim 1, wherein, The method uses a BAS evaluation system to simulate actual attack scenarios, verify the predictive accuracy of the risk transmission model, and calibrate the auxiliary variables in the model.
10. A multi-dimensional dynamic monitoring and early warning system for intelligent device security, characterized in that, The system includes: The device behavior chain digitization module is used to continuously monitor all operations and status changes of smart devices in real time, digitize their behavior to form a device behavior sequence, and identify abnormal sequences that deviate from the normal behavior pattern of smart devices. The abnormal sequences can be used as input for subsequent TTP prediction. The scene logic module is used to transform the preset smart home scene logic into an expected path model that can be used for security analysis, compare it with the abnormal sequence, and combine it with the causal chain of the TTP knowledge graph to determine whether the abnormal sequence constitutes a security risk. The risk visualization module is used to visually present the comparison results and security risk status in the form of a heat map, which is used to show the risk distribution and intensity of devices or areas. It can also integrate the analysis of unprotected major disaster types generated by TTP prediction and the protection effect diagram based on the ATT&CK framework. In addition, in the system, the risk transmission model based on TTP knowledge graph enhancement dynamically simulates the evolution and propagation process of the security risks in the smart device network, and integrates the attack paths and causal relationships predicted by TTP.
Citation Information
Patent Citations
Internet of Things smart home scene safety analysis method and device
CN113869753A
Information processing method based on Internet of Things equipment, related equipment and storage medium
CN114945028A
Comprehensive financial IT operation and maintenance management system and method based on artificial intelligence
CN120029858A
Network space security risk intelligent identification method and system
CN120546968A
Root cause positioning method and device, equipment, medium and program product
CN121031790A