Abnormality detection method and device for device behavior and electronic device
By employing two-way security authentication and encrypted channel transmission in the environmental monitoring system, combined with a zero-trust control mechanism, the security issues of identity authentication and data transmission in the environmental monitoring system are resolved, enabling dynamic and continuous monitoring and anomaly detection of equipment behavior.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TOWER CO LTD
- Filing Date
- 2025-12-10
- Publication Date
- 2026-07-31
AI Technical Summary
Existing environmental monitoring systems suffer from low security in identity authentication, insecure data transmission, and a lack of continuous trust verification. This makes it easy for device identities to be impersonated and data transmission risks high, making it impossible to effectively identify abnormal devices.
A two-way security authentication mechanism based on a preset encryption algorithm is adopted. The behavior characteristics of the device are verified by digital certificate signature and transmitted through encrypted channels. Combined with a zero-trust control mechanism, dynamic anomaly detection is performed to ensure the security of device identity authentication and data transmission.
It improves the security of device authentication and data transmission, enables dynamic and continuous monitoring of the behavior of environmental devices, prevents device identity spoofing and data leakage, and enhances the security and reliability of the system.
Smart Images

Figure CN121603281B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of environmental monitoring technology, and more specifically, to a method, apparatus, and electronic device for detecting abnormal equipment behavior. Background Technology
[0002] Existing technology provides a method for monitoring dynamic and environmental equipment. In this method, a monitoring module (SM) is set up for each power and environmental device (hereinafter referred to as dynamic and environmental equipment, including but not limited to switching power supply, UPS (Uninterruptible Power Supply), and backup battery). The monitoring module (SM) is used to monitor the operating data of the power and environmental equipment and upload the operating data to the monitoring unit (SU) via wired or wireless means. One monitoring unit (SU) can simultaneously connect to multiple monitoring modules (SM), forming a one-to-many access relationship. Then, the monitoring unit (SU) reports the summarized operating data to the centralized monitoring center (SC), thereby realizing real-time perception of the operating status of dynamic and environmental equipment and fault early warning.
[0003] While existing technologies, based on TCP / IP (Transmission Control Protocol / Internet Protocol) network architecture, have improved the scalability and operational efficiency of environmental monitoring systems, the data transmission between the monitoring module (SM) and the monitoring unit (SU) still suffers from the following security vulnerabilities:
[0004] (1) Low security of identity authentication: Existing environmental monitoring methods rely only on static IP (Internet Protocol) addresses, MAC (Media Access Control) addresses or simple credentials for identity recognition. Attackers can impersonate normal environmental devices through physical access or network spoofing, tamper with monitoring data or issue control commands.
[0005] (2) Data transmission security risks: The operation data or equipment instructions transmitted during the monitoring process are not encrypted with high-strength encryption methods, making them vulnerable to eavesdropping, tampering or replay attacks by man-in-the-middle;
[0006] (3) Lack of continuous trust verification mechanism: The existing environmental monitoring method is a "one-time authentication, long-term trust" model, which does not conform to the zero trust principle, cannot dynamically monitor the behavior of connected devices, and is difficult to identify long-term lurking abnormal devices or hijacked devices.
[0007] There is currently no effective solution to the above problems. Summary of the Invention
[0008] This application provides a method, apparatus, and electronic device for detecting abnormal equipment behavior, in order to at least solve the technical problem of low security in transmitting equipment behavior data when monitoring the behavior of environmental equipment based on existing technologies.
[0009] According to one aspect of this application, a method for detecting abnormal device behavior is provided, comprising: performing bidirectional security authentication on a first component and a second component based on a preset encryption algorithm, wherein the bidirectional security authentication is used to verify the signatures of digital certificates corresponding to the first component and the second component; establishing an encrypted channel between the first component and the second component after the first component and the second component pass the bidirectional security authentication; collecting behavioral data of the environmental device through the first component, extracting features from the behavioral data to obtain N behavioral features of the environmental device, wherein N is a positive integer; transmitting the N behavioral features to the second component through the encrypted channel; and performing abnormal device behavior detection on the environmental device through the second component based on the device type of the environmental device and the N behavioral features.
[0010] Optionally, before performing two-way security authentication on the first component and the second component based on a preset encryption algorithm, the abnormal device behavior detection method further includes: issuing digital certificates for the first component and the second component through a certificate authority; using the digital certificate of the first component as the first certificate, wherein the first certificate includes at least the component identifier, public key, and certificate validity period of the first component; and using the digital certificate of the second component as the second certificate, wherein the second certificate includes at least the component address and component identifier of the second component.
[0011] Optionally, based on a preset encryption algorithm, two-way security authentication is performed on the first component and the second component, including: encrypting the first certificate of the first component using the preset encryption algorithm to obtain a first encrypted value; encapsulating the first encrypted value to obtain a connection request of the first component, wherein the connection request includes at least the first encrypted value, a timestamp, and a random number generated by the first component; transmitting the connection request of the first component to the second component; determining the certificate status of the first certificate based on the connection request through the second component, wherein the certificate status is a valid status or an invalid status; and performing two-way security authentication on the first component and the second component based on the certificate status of the first certificate.
[0012] Optionally, based on the certificate status of the first certificate, two-way security authentication is performed on the first component and the second component, including: if the certificate status of the first certificate is valid, transmitting the second certificate of the second component to the first component; performing signature verification on the second certificate based on the root certificate stored in the first component, wherein the root certificate includes at least the public key of the certificate authority; after the second certificate passes signature verification, transmitting the first certificate of the first component to the second component; performing signature verification on the first certificate based on the root certificate stored in the second component; and after the first certificate passes signature verification, determining that the first component and the second component have passed two-way security authentication.
[0013] Optionally, based on the equipment type and N behavioral characteristics of the environmental monitoring equipment, anomaly detection is performed on the equipment behavior of the environmental monitoring equipment, including: determining N preset baseline characteristics of the environmental monitoring equipment based on its equipment type, wherein each preset baseline characteristic is used to characterize the average value of each historical behavioral characteristic of the environmental monitoring equipment within a historical period; obtaining the standard deviation corresponding to each of the N preset baseline characteristics, wherein the standard deviation is used to characterize the fluctuation range of the historical behavioral characteristics of the environmental monitoring equipment within a historical period; calculating the target deviation of the environmental monitoring equipment based on the N behavioral characteristics, the N preset baseline characteristics, and the standard deviation corresponding to each preset baseline characteristic; and performing anomaly detection on the equipment behavior of the environmental monitoring equipment based on the target deviation.
[0014] Optionally, based on the target deviation, anomaly detection is performed on the device behavior of the environmental monitoring equipment, including: when the target deviation is greater than or equal to a preset deviation, a target verification operation is performed, wherein the target verification operation includes at least one of the following sub-operations: a first sub-operation for re-signing and verifying the random number generated by the second component based on the private key of the first component; a second sub-operation for re-checking the certificate status of the first certificate of the first component; a third sub-operation for checking the consistency between the component identifier of the first component and the component identifier in the first certificate; when the target deviation is less than the preset deviation or the target verification operation is successful, the behavior state of the environmental monitoring equipment is determined to be normal; when the target verification operation fails, the behavior state of the environmental monitoring equipment is determined to be abnormal.
[0015] Optionally, after detecting anomalies in the behavior of the environmental monitoring equipment, the method for detecting anomalies in equipment behavior further includes: when the behavior state of the environmental monitoring equipment is normal, updating the behavior baseline data of the environmental monitoring equipment based on N behavior features, wherein the behavior baseline data includes at least N preset baseline features and the standard deviation corresponding to each preset baseline feature; when the behavior state of the environmental monitoring equipment is abnormal, cutting off the encrypted channel, generating alarm information, and recording the N behavior features of the environmental monitoring equipment through logs.
[0016] According to another aspect of this application, an anomaly detection device for device behavior is also provided, comprising: a two-way authentication unit, used to perform two-way security authentication on a first component and a second component based on a preset encryption algorithm, wherein the two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component; a channel establishment unit, used to establish an encrypted channel between the first component and the second component after the first component and the second component pass the two-way security authentication; a feature extraction unit, used to collect behavioral data of the environmental device through the first component, extract features from the behavioral data, and obtain N behavioral features of the environmental device, wherein N is a positive integer; a feature transmission unit, used to transmit the N behavioral features to the second component through the encrypted channel; and an anomaly detection unit, used to perform anomaly detection on the device behavior of the environmental device through the second component based on the device type of the environmental device and the N behavioral features.
[0017] According to another aspect of this application, a computer program product is also provided, which stores a computer program, wherein an abnormal detection method controls the computer program product to perform any of the above-mentioned device behaviors when the computer program is running.
[0018] According to another aspect of this application, an electronic device is also provided, wherein the electronic device includes one or more processors and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to perform an anomaly detection method for device behavior as described above.
[0019] In this application, firstly, based on a preset encryption algorithm, a two-way security authentication is performed on the first component and the second component. The two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component. After the first component and the second component pass the two-way security authentication, an encrypted channel is established between the first component and the second component. Subsequently, the first component collects behavioral data of the environmental monitoring device, extracts features from the behavioral data, and obtains N behavioral features of the environmental monitoring device, where N is a positive integer. The N behavioral features are transmitted to the second component through the encrypted channel. Then, the second component performs anomaly detection on the device behavior of the environmental monitoring device based on the device type of the environmental monitoring device and the N behavioral features.
[0020] As can be seen from the above, this application collects behavioral data of environmental devices through the first component and uses a preset encryption algorithm to perform two-way security authentication on the first and second components. By adding a security authentication mechanism and a zero-trust control mechanism, it achieves the purpose of improving the security of identity authentication and data transmission between the first and second components. This avoids the defects of traditional monitoring systems, such as easy impersonation of device identities, high data transmission security risks, and lack of dynamic monitoring of the behavior of connected devices. Thus, it achieves the technical effect of dynamic and continuous security authentication and secure data transmission between the first and second components, thereby solving the technical problem of low security in transmitting device behavior data when monitoring the behavior of environmental devices based on existing technologies. Attached Figure Description
[0021] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0022] Figure 1 This is a flowchart of an optional method for detecting abnormal device behavior according to an embodiment of this application;
[0023] Figure 2 This is an architecture diagram of an optional device behavior anomaly detection system according to an embodiment of this application;
[0024] Figure 3 This is a timing diagram of an optional two-way security authentication method based on a preset encryption algorithm according to an embodiment of this application;
[0025] Figure 4 This is a schematic diagram of an optional method for calculating target deviation according to an embodiment of this application;
[0026] Figure 5 This is a flowchart of an optional method for detecting abnormalities in environmental equipment according to an embodiment of this application;
[0027] Figure 6 This is a schematic diagram of an optional device behavior anomaly detection device according to an embodiment of this application;
[0028] Figure 7 This is a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0029] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0031] It should also be noted that all relevant information (including but not limited to information related to user flight segments) and data (including but not limited to data used for display and analysis) involved in this application are information and data authorized by the user or fully authorized by all parties. For example, if there is an interface between this system and the relevant user or organization, before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information only after receiving consent from the aforementioned user or organization.
[0032] Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of relevant information and data involved in this application all comply with the relevant laws, regulations, and standards of the relevant regions, and necessary confidentiality measures have been taken. This application does not violate public order and good morals. In addition, this application provides a corresponding operation entry point for users to choose to agree to or refuse authorization. If the user chooses to refuse authorization, the corresponding expert decision-making process will be initiated.
[0033] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:
[0034] Environmental monitoring equipment: including the first component and the second component.
[0035] The first component refers to monitoring devices, including but not limited to multiple monitoring gateways and monitoring units (SU).
[0036] The second component refers to a monitoring module (SM) integrated into the monitored equipment (i.e., power and environmental equipment, or simply environmental equipment). The monitoring module (SM) is one of the following:
[0037] Switching power supply monitoring module: used to monitor the voltage, current and temperature of the power supply;
[0038] Uninterruptible power supply (UPS) monitoring module: used to monitor the UPS battery status, load status, and power mode;
[0039] Temperature and humidity sensor: used to monitor changes in ambient temperature and humidity;
[0040] Air conditioning monitoring module: used to control and monitor the operating status and settings parameters of the air conditioner;
[0041] Environmental sensors: used to detect security incidents such as smoke, water immersion, and access control.
[0042] The present invention will now be described in detail with reference to various embodiments.
[0043] Example 1
[0044] According to an embodiment of this application, an embodiment of a method for detecting abnormal device behavior is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0045] This application provides an anomaly detection system for equipment behavior (hereinafter referred to as the detection system) for executing the anomaly detection method for equipment behavior in this application. Figure 1 This is a flowchart of an optional device behavior anomaly detection method according to an embodiment of this application, such as... Figure 1 As shown, the method includes the following steps:
[0046] Step S101: Based on a preset encryption algorithm, perform two-way security authentication on the first component and the second component, wherein the two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component.
[0047] Optionally, a preset encryption algorithm is used, specifically the SM2 / SM3 / SM4 (Specification of SM2 / SM3 / SM4, commercial SM2 / SM3 / SM4) encryption algorithm. The detection system generates digital signatures, encrypts data, and verifies data integrity based on the preset encryption algorithm, thereby ensuring the security of the operation / behavior / command data of the environmental monitoring equipment during transmission.
[0048] Optionally, both the first component and the second component are environmental monitoring devices.
[0049] Optionally, the first component refers to monitoring devices, including but not limited to multiple monitoring gateways and monitoring units (SUs).
[0050] Optionally, the second component refers to a monitoring module (SM) integrated into the monitored equipment (i.e., power and environmental equipment, or simply environmental equipment).
[0051] Optionally, a two-way security authentication mechanism, namely mTLS (Mutual Transport Layer Security), is used. This mechanism differs from the traditional TLS (Transport Layer Security) method where only the server verifies the client's TLS. mTLS requires both parties (SM and SU) involved in the authentication to provide digital certificates and verify the validity of each other's digital certificates, thereby achieving two-way secure identity authentication between the two components.
[0052] Optionally, signature verification, i.e., the first and second components verify the signature of the other party's digital certificate to ensure the compliance and integrity of the digital certificate provided by the other party.
[0053] In step S101, the detection system achieves the following function by performing two-way secure authentication (mTLS) on the first component and the second component:
[0054] (1) Enhance the security of identity authentication: By performing two-way authentication between the first component and the second component, the system avoids third parties from impersonating normal SMs and communicating with SUs, thereby improving the overall security of the detection system.
[0055] (2) Algorithm self-controllability: The two-way security authentication process adopts the SM2 / SM3 / SM4 algorithm, which complies with the existing cryptographic application standards, ensures the self-controllability of the encryption process, and meets compliance requirements.
[0056] Step S102: After the first component and the second component pass the two-way security authentication, an encrypted channel is established between the first component and the second component.
[0057] Optionally, the encrypted channel refers to a secure communication channel established between the SM and the SU, which uses the SM4-GCM (SM4-Galois Counter Mode, the Galois Counter Mode of the commercial cryptographic algorithm SM4) encryption mode to ensure the confidentiality, integrity and replay resistance of data during transmission.
[0058] In step S102, the detection system establishes an encrypted channel to provide a secure data transmission environment, reducing the risk of data being eavesdropped on, tampered with, and replayed, and effectively preventing man-in-the-middle attacks on the data transmission process.
[0059] Step S103: Collect behavioral data of the environmental equipment through the first component, extract features from the behavioral data, and obtain N behavioral features of the environmental equipment, where N is a positive integer.
[0060] Optionally, behavioral data refers to various types of operational data generated by the device during operation that reflect its behavior.
[0061] Optionally, the N behavioral characteristics include, but are not limited to, the sampling frequency, data fluctuation range, command response time, data format compliance rate, and connection stability of the environmental monitoring equipment.
[0062] For example, the feature description text and configuration logic of behavioral features of different feature types are shown in Table 1 below.
[0063] Table 1
[0064]
[0065] Optionally, when the first component collects the operation / behavior data of the environmental monitoring equipment, it follows the least privilege policy. That is, the first component determines the data collection range and equipment permission range corresponding to the equipment based on the equipment type of the environmental monitoring equipment. For example, the temperature and humidity sensor is only allowed to report temperature and humidity parameters, and the UPS monitoring module is only allowed to report battery parameters and control power.
[0066] Optionally, the detection system extracts features from the behavioral data of the environmental equipment to obtain N behavioral features, thereby achieving the goal of monitoring the operating behavior of the environmental equipment from multiple perspectives, improving the accuracy of abnormal detection of the environmental equipment, and through feature extraction, achieving the goal of vectorizing the behavioral data, reducing the amount of data that needs to be transmitted between the first component and the second component.
[0067] Step S104: Transmit N behavioral features to the second component via an encrypted channel.
[0068] Optionally, the detection system transmits N behavioral features through an encrypted channel, which can achieve the following:
[0069] (1) Improve the security of data transmission: By transmitting behavioral characteristics through encrypted channels, data leakage during transmission can be prevented. Even if the data is intercepted, it cannot be deciphered, effectively resisting man-in-the-middle attacks.
[0070] (2) Ensure data integrity and anti-replay capability: SM4-GCM can not only encrypt the data to be transmitted (i.e. N behavioral features), but also provide integrity verification and anti-replay attack capabilities, ensuring that the data is not tampered with during transmission and preventing old data from being maliciously retransmitted, thus ensuring the timeliness and validity of the data.
[0071] (3) Zero Trust Secure Access: The behavioral characteristics are securely transmitted to the SU, enabling the SU to continuously detect anomalies in device behavior based on real-time behavioral characteristics, combined with device type and behavioral characteristic baseline, and to achieve zero trust dynamic security assessment.
[0072] Step S105: Using the second component, anomaly detection is performed on the device behavior of the environmental equipment based on the equipment type and N behavioral characteristics of the environmental equipment.
[0073] Optionally, during the anomaly detection process, the detection system first determines the behavioral baseline data corresponding to the device based on the device type of the environmental device. The behavioral baseline data includes at least N preset baseline features of the environmental device and the standard deviation corresponding to each preset baseline feature. Each preset baseline feature is used to characterize the average value of each historical behavioral feature of the environmental device in the historical period.
[0074] Subsequently, the detection system continuously monitors and analyzes the deviation between N behavioral characteristics and the behavioral baseline data, thereby detecting abnormal situations that do not conform to the preset normal behavioral baseline, such as device hijacking, software failure, etc.
[0075] Optionally, the detection system can perform anomaly detection on the behavior of the environmental monitoring equipment based on the equipment type and N behavioral characteristics, thereby achieving the following functions:
[0076] (1) Dynamic security protection: The continuous verification mechanism under the zero trust concept can monitor device behavior in real time, dynamically identify anomalies, and realize the transformation from static authentication to dynamic trust.
[0077] (2) Refined anomaly identification: Anomaly detection based on device type and behavioral characteristics can more accurately identify abnormal behavior, avoid false alarms, and improve the timeliness and accuracy of security response.
[0078] Optionally, when establishing an encrypted channel between the first component and the second component, and transmitting the environmental equipment operation / behavior data reported by the first component or the equipment instructions issued by the second component through the encrypted channel, the following steps are included:
[0079] (1) Session key negotiation: The master key is generated through SM2 key exchange, and then the SM4 session key is generated through SM3-KDF key derivation function. ;
[0080] (2) Data encryption and integrity verification: The data to be transmitted is encrypted using SM4-GCM mode. The encryption process is shown in the following formula:
[0081] ;
[0082] in, It is a 12-byte random vector (randomly generated for each encryption). The plaintext of the data to be transmitted. To add authentication data, This is an encrypted message containing a 128-bit tag. When SU decrypts the message, it verifies the tag and discards the message if the tag does not match.
[0083] Optionally, when transmitting encrypted messages, the sequence number of the encrypted message is determined by... ( The data increments linearly, and the monitoring unit (SU) stores the latest data. ,like or If there is a mismatch, it is considered a replay attack. , It is an authentication tag generated by calculating the data packet using the SM3 hash function. This refers to the actual message data in the current nth data packet.
[0084] As can be seen from the above, this application collects behavioral data of environmental devices through the first component and uses a preset encryption algorithm to perform two-way security authentication on the first and second components. By adding a security authentication mechanism and a zero-trust control mechanism, it achieves the purpose of improving the security of identity authentication and data transmission between the first and second components. This avoids the defects of traditional monitoring systems, such as easy impersonation of device identities, high data transmission security risks, and lack of dynamic monitoring of the behavior of connected devices. Thus, it achieves the technical effect of dynamic and continuous security authentication and secure data transmission between the first and second components, thereby solving the technical problem of low security in transmitting device behavior data when monitoring the behavior of environmental devices based on existing technologies.
[0085] In one alternative embodiment, Figure 2 This is an architecture diagram of an optional device behavior anomaly detection system according to an embodiment of this application, such as... Figure 2 As shown, the system architecture includes: a hardware security layer, a security authentication layer, an environmental monitoring function layer, and a zero-trust control layer. Each layer works together to embed security protection capabilities without affecting the existing environmental monitoring business processes.
[0086] Optionally, in the hardware security layer, the second component, namely the monitoring module (SM), adopts a low-power MCU (Microcontroller Unit) with an integrated secure element (SE), and the private key is securely stored in the SE; the monitoring unit (SU) integrated in the first component integrates a hardware encryption chip, supports hardware acceleration of SM2 / SM3 / SM4 algorithms, and ensures the physical security of the key and the operation.
[0087] Optionally, an mTLS protocol module is integrated into the security authentication layer, supporting SM2 / SM3 / SM4 encryption algorithms to achieve two-way authentication and TLS encrypted communication between the monitoring module (SM) and the monitoring unit (SU).
[0088] Optionally, in the environmental monitoring function layer, the core functions of the existing environmental system are retained, including but not limited to: device access, data acquisition, protocol parsing, command issuance and interface with the centralized monitoring center (SC), and security logic is embedded in each business process in a non-intrusive manner.
[0089] Optionally, the zero-trust control layer includes three modules:
[0090] (1) Continuous verification module: Combining OCSP (Online Certificate Status Protocol) status query with a baseline set of behavioral features based on device type, the degree of device abnormality is quantified by a weighted behavioral deviation model.
[0091] (2) Access control module: Implement the least privilege policy based on the device type (e.g., temperature and humidity sensors are only allowed to report data, while UPS is allowed to report and has limited control).
[0092] (3) Anomaly audit module: Records all security events and operation logs (data modification, instruction issuance), uses SM3 hash encryption for storage, and supports tamper-proof audit tracing.
[0093] Optionally, Figure 2 The Certificate Authority (CA) in the system is built on a preset encryption algorithm and supports the issuance of digital certificates that conform to preset standards by SM2. The certificate extension field embeds the device type and compliance identifier (such as "GM0001") and provides low-latency OCSP (Online Certificate Status Protocol) service (response time ≤100ms).
[0094] In one optional embodiment, before performing two-way security authentication on the first component and the second component based on a preset encryption algorithm, the detection system needs to issue digital certificates for the first component and the second component. This process includes: first, issuing digital certificates for the first component and the second component through a certificate authority; then, the detection system uses the digital certificate of the first component as the first certificate, wherein the first certificate includes at least the component identifier, public key, and certificate validity period of the first component; and then, the detection system uses the digital certificate of the second component as the second certificate, wherein the second certificate includes at least the component address and component identifier of the second component.
[0095] Optionally, a Certificate Authority (CA) refers to an organization responsible for issuing and managing digital certificates, which uses a preset encryption algorithm (such as SM2) to generate digital certificates that conform to a preset standard.
[0096] Optionally, a digital certificate refers to an electronic document used to prove the identity of network communication entities (such as the first component and the second component), containing the entity's identification information (such as component identifier, public key, etc.) and the CA's digital signature, used to implement authentication in the mTLS two-way authentication process.
[0097] Optionally, the detection system issues digital certificates for the first and second components by controlling the certificate authority, thereby providing verifiable entity identities for the first and second components.
[0098] Optionally, the detection system, by embedding the component identifier, public key, and certificate validity period of the first component into the first certificate, has the following functions:
[0099] (1) Uniqueness of identity: The component identifier ensures that the identity of each SM is unique, preventing counterfeit devices from accessing the network.
[0100] (2) Public key is used for encryption, decryption and authentication: The public key is used for encryption and signature verification in the mTLS authentication process to ensure communication security.
[0101] (3) Certificate validity period management Certificate lifecycle: Set the validity period of the certificate to facilitate the periodic renewal and revocation of the certificate and maintain the security status of the system.
[0102] Optionally, the detection system, by embedding the component address and component identifier of the second component in the second certificate, has the following functions:
[0103] (1) Component address is used for location and identification: The IP address information of SU makes it easy for SM to accurately locate when initiating a connection, which is the basis of network communication.
[0104] (2) Component Identifier Ensures Uniqueness: The presence of the component identifier in the second certificate ensures the uniqueness of the SU's identity and prevents identity impersonation.
[0105] (3) Enhance the security of the communication process: In the mTLS two-way authentication process, the second certificate of SU works with the first certificate of SM to perform two-way security authentication, thus building a secure communication environment for the first and second components.
[0106] In summary, the detection system provides data verification assurance for the secure access and behavior monitoring of environmental devices. Among them, the issuance of digital certificates ensures the legitimacy and uniqueness of the identities of both communicating parties, providing verification credentials for subsequent mTLS two-way authentication.
[0107] In one optional embodiment, the detection system first encrypts the first certificate of the first component using a preset encryption algorithm to obtain a first encrypted value. Then, the detection system encapsulates the first encrypted value to obtain a connection request for the first component. The connection request includes at least the first encrypted value, a timestamp, and a random number generated by the first component. The detection system then transmits the connection request of the first component to the second component. Subsequently, the detection system uses the second component to determine the certificate status of the first certificate based on the connection request. The certificate status is either valid or invalid. Then, based on the certificate status of the first certificate, the detection system performs bidirectional security authentication on the first component and the second component.
[0108] Optionally, the detection system performs a hash calculation on the first certificate based on a preset encryption algorithm, and uses the calculated hash value as the first encrypted value. Subsequently, the detection system encapsulates the first encrypted value, the timestamp, and the random number generated by the first component to obtain the connection request data initiated by the first component to the second component. By encrypting the first certificate, the detection system can prevent the certificate content of the digital certificate from being intercepted and deciphered.
[0109] Optionally, the timestamp refers to the time stamp added to the connection request to prevent replay attacks and ensure the timeliness of each communication. Similarly, the random number refers to the random number generated by the first component (SM) and is also used to prevent replay attacks, ensure the uniqueness of each connection request, and improve the security of the connection request.
[0110] Optionally, the detection system marks the beginning of the mTLS two-way security authentication process by sending the connection request from the first component to the second component. After receiving the connection request, the second component queries the Certificate Authority (CA) for the validity of the first certificate through the Online Certificate Status Protocol (OCSP) to determine whether the first certificate is in a valid state. Based on the OCSP query mechanism, the detection system can detect the validity of the first certificate in real time, avoid using a revoked or expired first certificate, and enhance the security and trustworthiness of the communication process between the first component and the second component.
[0111] Optionally, after obtaining the certificate status of the first certificate and confirming that the first certificate is valid, the first and second components perform mTLS mutual authentication. That is, the second component verifies the identity of the first component through the first certificate, and the first component also verifies the certificate status and identity of the first component. The two parties establish a valid trust relationship based on the certificate, which provides a trust foundation for the subsequent establishment of encrypted channels and data transmission. Among them, mTLS mutual authentication provides higher security than one-way authentication, effectively prevents the access of malicious entities, and reduces the risk of the entire detection system being attacked.
[0112] In one optional embodiment, when the certificate status of the first certificate is valid, the detection system transmits the second certificate of the second component to the first component. Then, the detection system performs signature verification on the second certificate based on the root certificate stored in the first component, wherein the root certificate includes at least the public key of the certificate authority. After the second certificate passes the signature verification, the detection system transmits the first certificate of the first component to the second component. Subsequently, the detection system performs signature verification on the first certificate based on the root certificate stored in the second component. After the first certificate passes the signature verification, the detection system determines that the first component and the second component have passed the two-way security authentication.
[0113] Optionally, the certificate status of the first certificate refers to the status of the first certificate obtained by the second component through OCSP. If the certificate status of the first certificate is valid, it indicates that the first component connected at this time is a trusted entity device, and the two can continue to perform the two-way security verification process.
[0114] Optionally, if the certificate status of the first certificate is valid, the second component transmits its second certificate to the first component, enabling the second component to verify the identity of the first component, thus laying a trust foundation for establishing an encrypted communication channel and enhancing the security of the communication network between the first and second components.
[0115] Optionally, both the first and second components pre-store root certificates issued by a Certificate Authority (CA).
[0116] Optionally, the root certificate is the highest-level digital certificate issued by a Certificate Authority (CA). The CA's public key is used to verify the signatures of all lower-level digital certificates, ensuring the integrity and trustworthiness of the certificate chain.
[0117] Optionally, the detection system verifies the signature of the second certificate based on the root certificate stored in the first component, thereby verifying the integrity and authenticity of the second certificate. Since the second certificate is issued by a trusted CA, verifying the signature of the second certificate based on the root certificate enhances the first component's trust in the identity of the second component. At the same time, verification through the root certificate complies with the verification rules of the PKI (Public Key Infrastructure) trust chain, thus improving the compliance and security of the entire two-way security verification process.
[0118] Optionally, after the second certificate passes signature verification, the detection system transmits the first certificate of the first component to the second component to complete the two-way information exchange in mTLS two-way authentication, ensuring that the second component can also verify the identity of the first component and achieve true two-way trust.
[0119] Optionally, after the second component receives the first certificate, the detection system performs signature verification on the first certificate based on the root certificate stored in the second component. Through signature verification, the second component detects whether the first certificate has been forged or tampered with, thus forming a complete closed loop of two-way authentication and enhancing the security of the detection system.
[0120] Optionally, after both the first and second certificates have been verified by the other party's signature, the first and second components confirm each other's identity, establish mutual trust, provide a secure environment for the establishment of subsequent encrypted channels, and establish a security framework that conforms to zero trust.
[0121] Optionally, even after the SU and SM have passed two-way security authentication, the monitoring unit (SU) will periodically (e.g., every 5 minutes) or event-triggered (e.g., revocation notification) query the certificate status of the monitoring module (SM). If the certificate is invalid, the connection will be terminated immediately and the information will be reported to the centralized monitoring center (SC).
[0122] In summary, by performing the above steps, the first and second components can establish a secure and reliable encrypted communication channel while ensuring the legitimacy of both parties' identities, thereby achieving secure data transmission. This meets the requirement of strict verification of each connection under the zero-trust security framework, improving the security of the detection system and the confidentiality of the data.
[0123] In one alternative embodiment, Figure 3 This is a timing diagram of an optional two-way security authentication method based on a preset encryption algorithm according to an embodiment of this application, such as... Figure 3 As shown, the method includes: a certificate pre-configuration phase, a device self-discovery phase, and an encrypted data transmission phase.
[0124] Optionally, during the certificate pre-configuration phase, the CA issues a unique national cryptographic certificate (including device serial number, public key, and validity period) for each legitimate SM, and the private key is written into the SE chip after being encrypted with SM4; the monitoring unit (SU) obtains the server certificate bound to its IP and device number, and the private key is stored in the encrypted storage area; both the monitoring module (SM) and the monitoring unit (SU) are pre-configured with the CA's root certificate.
[0125] Optionally, during the device discovery phase, after the monitoring module (SM) is powered on, it initiates a secure connection request to the SU. The secure connection request carries the SM3 hash value (H), timestamp, and random number of its certificate. Then, the monitoring unit (SU) verifies the validity of the digital certificate corresponding to the hash value (H) through OCSP. If the digital certificate corresponding to the hash value (H) is in an unrevoked state (i.e., a valid state), the monitoring unit (SU) returns its own certificate. The monitoring module (SM) uses the CA root certificate to verify the identity of the monitoring unit (SU) through SM2 signature. After that, the monitoring module (SM) returns its own certificate, and the two parties exchange complete certificates. After completing two-way authentication, they negotiate TLS and establish a TLS_SM4_GCM_SM3 encrypted channel.
[0126] Optionally, after establishing the TLS_SM4_GCM_SM3 encrypted channel, the encrypted data transmission phase begins, and the monitoring module (SM) can start reporting monitoring data or receiving control commands issued by the monitoring unit.
[0127] In one optional embodiment, the detection system first determines N preset baseline features of the environmental monitoring equipment (ERE) based on its equipment type. Each preset baseline feature is used to characterize the average value of each historical behavior feature of the ERE within a historical period. Then, the detection system obtains the standard deviation corresponding to each of the N preset baseline features. The standard deviation is used to characterize the fluctuation range of the historical behavior features of the ERE within a historical period. Subsequently, the detection system calculates the target deviation of the ERE based on the N behavior features, the N preset baseline features, and the standard deviation corresponding to each preset baseline feature. Finally, the detection system performs anomaly detection on the equipment behavior of the ERE based on the target deviation.
[0128] Optionally, different types of environmental monitoring devices exhibit different behaviors. Therefore, the user baseline data (i.e., preset baseline features and standard deviation) corresponding to different types of environmental monitoring devices are also different. The detection system determines N preset baseline features of the environmental monitoring device based on the device type, making the abnormal detection results of the environmental monitoring device more targeted and improving the accuracy of abnormal detection.
[0129] Optionally, the detection system implements a safety guidance strategy based on normal historical behavior data by setting preset baseline characteristics for the environmental equipment. The detection system uses the average value of historical behavior characteristics to measure the real-time behavior characteristic value, and can understand the deviation between the current behavior characteristics and historical behavior characteristics of the environmental equipment, thereby realizing the detection of anomalies in the environmental equipment.
[0130] Optionally, the standard deviation is used to measure the range of fluctuation of the real-time behavioral characteristics of a dynamic environment device relative to its historical average. The introduction of the standard deviation has the following functions:
[0131] (1) Quantifying behavioral fluctuations: The introduction of standard deviation enables the system to quantify the fluctuation range of each behavioral feature, providing a data basis for the subsequent calculation of target deviation.
[0132] (2) Dynamic safety threshold: The detection threshold for abnormal behavior is dynamically adjusted according to the standard deviation, which enhances the flexibility and adaptability of the system.
[0133] In one alternative embodiment, Figure 4 This is a schematic diagram of an optional method for calculating target deviation according to an embodiment of this application, as shown below. Figure 4 As shown, the detection system calculates the target deviation based on real-time behavioral feature values, preset baseline values, historical representation differences, and feature weights. .
[0134] Optionally, target deviation The calculation formula is as follows:
[0135] ;
[0136] The parameters are defined as follows:
[0137] The weight of the i-th behavioral feature (i.e. Figure 4 (feature weights in the middle)
[0138] N: The number of dimensions of the behavioral features associated with the current environmental equipment (N≥1);
[0139] The real-time monitoring value of the i-th behavioral characteristic of the environmental equipment (i.e. Figure 4 (real-time behavioral feature values in the data).
[0140] : The preset baseline value (i.e., preset baseline feature) of the i-th behavioral feature of the environmental equipment.
[0141] : The standard deviation corresponding to the preset baseline value of the i-th behavioral feature (i.e. Figure 4 (historical standard deviation).
[0142] Optionally, by performing weighted calculations based on the above formula, the detection system can more accurately reflect the impact of different behavioral characteristics on the overall safety status of the equipment, avoiding misjudgments caused by a single characteristic indicator.
[0143] Optionally, the calculation of target deviation has the following functions:
[0144] (1) Automated behavior assessment: The calculation of target deviation enables automated assessment of the behavior of environmental equipment without manual intervention, thus improving monitoring efficiency.
[0145] (2) Quantifying abnormal behavior: Measuring the degree of abnormality of device behavior by measuring the deviation of the target helps to set specific abnormality detection thresholds, making abnormality detection more scientific and accurate.
[0146] (3) Based on the target deviation, perform abnormal detection on the equipment behavior of the dynamic environment equipment.
[0147] In summary, by executing the aforementioned weighted steps, the detection system can dynamically calculate the target deviation based on the device type and by using the behavioral characteristic baseline and standard deviation statistically derived from historical data. This enables automated detection of abnormal device behavior. This mechanism not only improves the targeting and accuracy of device behavior monitoring but also achieves dynamic risk perception and closed-loop handling under a zero-trust security framework, thereby enhancing the overall security protection level of the detection system.
[0148] In one optional embodiment, after calculating the target deviation, if the target deviation is greater than or equal to a preset deviation, the detection system performs a target inspection operation. Then, if the target deviation is less than the preset deviation or the target inspection operation is successfully verified, the detection system determines that the behavior state of the dynamic environment equipment is normal; if the target inspection operation fails to verify, the behavior state of the dynamic environment equipment is determined to be abnormal.
[0149] Optionally, the target inspection operation includes at least one of the following sub-operations:
[0150] The first sub-operation is used to re-sign and verify the random number generated by the second component based on the private key of the first component;
[0151] The second sub-operation is used to re-check the certificate status of the first certificate of the first component;
[0152] The third sub-operation is used to check the consistency between the component identifier of the first component and the component identifier in the first certificate.
[0153] Optionally, if the target deviation is greater than or equal to a preset deviation, the detection system performs a secondary inspection, with the following function:
[0154] (1) By performing the first sub-operation, the signature verification is re-performed, ensuring that even if the device is controlled by a long-term lurking attacker, the anomaly can be detected in time, thus enhancing the system's ability to resist covert attacks.
[0155] (2) By performing the second sub-operation, the certificate status of the first certificate of the first component is re-checked to ensure that the certificate has not been revoked, which increases the verification depth of the device's legitimacy. At the same time, the re-checking of the certificate status can effectively prevent the access of counterfeit devices. Even if their behavior characteristics are temporarily similar to the baseline, they can be identified through the certificate status check.
[0156] (3) By performing the third sub-operation, the component identifier of the first component is re-checked to see if it is consistent with the component identifier in the first certificate. This provides physical-level device verification, enhances the credibility of the device identity, and at the same time, even if the private key is obtained, the consistency check of the hardware identifier can prevent attackers from using the private key to perform illegal operations, thus improving the security defense of the system.
[0157] Optionally, by combining the target deviation and the results of the target inspection operation, the detection system can accurately determine the behavior status of the equipment, providing a safety basis for subsequent action decisions (such as data collection, command issuance, etc.).
[0158] In summary, by executing the aforementioned subordinate steps, the detection system can perform fine-grained, multi-layered verification of devices when their behavior deviates from normal patterns, promptly identifying and responding to potential security threats. This mechanism not only enhances the system's dynamic security protection capabilities but also ensures that, under a zero-trust framework, every action of every device can be meticulously inspected and reasonably evaluated, thereby improving the security and stability of the entire monitoring network.
[0159] In one optional embodiment, after detecting anomalies in the behavior of the environmental monitoring device, if the behavior of the environmental monitoring device is in a normal state, the detection system updates the behavior baseline data of the environmental monitoring device based on N behavior features. The behavior baseline data includes at least N preset baseline features and the standard deviation corresponding to each preset baseline feature. Then, if the behavior of the environmental monitoring device is in an abnormal state, the detection system cuts off the encrypted channel, generates alarm information, and records the N behavior features of the environmental monitoring device through logs.
[0160] Optionally, the detection system updates the baseline behavioral data of the environmental equipment based on N behavioral characteristics that indicate normal operation, and has the following functions:
[0161] (1) Self-learning and adaptation: The system updates the behavior baseline data when the equipment is behaving normally, and can learn and adapt itself according to the actual operation of the equipment, thereby improving the accuracy and effectiveness of the baseline.
[0162] (2) Dynamically adjust security strategies: Updating behavioral baseline data enables security strategies to be dynamically adjusted to better cope with environmental changes and equipment aging, ensuring the timeliness of security strategies.
[0163] Optionally, when the behavior of the environmental monitoring equipment is abnormal, the detection system disconnects the encrypted channel, generates an alarm message, and records relevant data through the log, serving the following purposes:
[0164] (1) Fast security response: Immediately cut off the encrypted channel to prevent potential threats from further affecting the system and improve the system's security response speed.
[0165] (3) Alarm and audit integration: By generating alarm information and detailed behavior characteristic logs, the system can promptly notify managers to take measures, while maintaining complete event records for easy post-event auditing and analysis.
[0166] (4) Enhanced defense mechanism: When the device behaves abnormally, measures such as cutting off the encrypted channel and generating alarms are taken. This is an important manifestation of dynamic protection under the zero-trust security framework and enhances the overall defense capability of the system.
[0167] Optionally, by implementing the above steps, the detection system can intelligently update the behavior baseline data based on whether the device's behavior is normal or abnormal. At the same time, it can respond quickly when abnormal behavior is detected, cut off risk channels and record detailed logs, ensuring the security and stability of the monitoring network. It also has the ability to learn and adapt dynamically, improving the flexibility and effectiveness of security strategies.
[0168] In one alternative embodiment, Figure 5 This is a flowchart of an optional method for detecting abnormalities in environmental equipment according to an embodiment of this application, such as... Figure 5 As shown, the detection system first calculates the behavioral deviation of the environmental equipment based on the collected equipment behavior data. (i.e., target deviation), and then, configure differentiated deviation thresholds for different device types. (i.e., preset deviation).
[0169] Optionally, in behavioral deviation Greater than or equal to the deviation threshold In this case, secondary verification (i.e., target inspection operation) is triggered. The verification content of secondary verification includes:
[0170] (1) The device is required to use the SE chip to perform SM2 signature on the random number (Rand) generated by SU;
[0171] (2) Verify the validity of the current TLS session certificate of the device (query OCSP in real time);
[0172] (3) Verify the consistency between the device hardware feature code (such as the MCU unique identifier, SE chip serial number) and the certificate binding information;
[0173] Optionally, if the secondary verification fails and the currently accessed environmental monitoring device is determined to be an abnormal device, the monitoring unit (SU) immediately terminates the TLS connection with the device and refuses to receive subsequent device behavior data reported by the monitoring module. At the same time, the SU reports an alarm message to the SC with the content of "abnormal behavior - authentication failure". The alarm message also carries the device serial number, abnormal feature type and deviation value, and records an abnormal log (including real-time value, baseline value and deviation calculation process). The log is stored using SM3 hash encryption.
[0174] Optionally, if the secondary verification is successful / behavioral deviation Less than the deviation threshold If the current access environmental monitoring device is determined to be a normal device, the behavior monitoring of the device will continue. At the same time, the behavior baseline value of the device will be updated based on the behavior data of the environmental monitoring device collected in real time. Then, the next round of monitoring process will be started.
[0175] As can be seen from the above, this application collects behavioral data of environmental devices through the first component and uses a preset encryption algorithm to perform two-way security authentication on the first and second components. By adding a security authentication mechanism and a zero-trust control mechanism, it achieves the purpose of improving the security of identity authentication and data transmission between the first and second components. This avoids the defects of traditional monitoring systems, such as easy impersonation of device identities, high data transmission security risks, and lack of dynamic monitoring of the behavior of connected devices. Thus, it achieves the technical effect of dynamic and continuous security authentication and secure data transmission between the first and second components, thereby solving the technical problem of low security in transmitting device behavior data when monitoring the behavior of environmental devices based on existing technologies.
[0176] Example 2
[0177] This application embodiment can also provide a device for detecting abnormal device behavior. It should be noted that the device for detecting abnormal device behavior in this application embodiment can be used to execute the device behavior abnormal detection method provided in this application embodiment. The device for detecting abnormal device behavior provided in this application embodiment will be described below.
[0178] According to an embodiment of this application, an apparatus for implementing the above-described method for detecting abnormal device behavior is also provided. Figure 6This is a schematic diagram of an optional device behavior anomaly detection device according to an embodiment of this application, such as... Figure 6 As shown, the device includes: a two-way authentication unit 601, a channel establishment unit 602, a feature extraction unit 603, a feature transmission unit 604, and an anomaly detection unit 605.
[0179] Optionally, the two-way authentication unit 601 is used to perform two-way security authentication on the first component and the second component based on a preset encryption algorithm, wherein the two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component; the channel establishment unit 602 is used to establish an encrypted channel between the first component and the second component after the first component and the second component pass the two-way security authentication; the feature extraction unit 603 is used to collect the behavior data of the environmental monitoring device through the first component, extract features from the behavior data, and obtain N behavior features of the environmental monitoring device, wherein N is a positive integer; the feature transmission unit 604 is used to transmit the N behavior features to the second component through the encrypted channel; and the anomaly detection unit 605 is used to perform anomaly detection on the device behavior of the environmental monitoring device through the second component based on the device type of the environmental monitoring device and the N behavior features.
[0180] In one optional embodiment, the device for detecting abnormal device behavior further includes: a digital certificate issuing unit, a first certificate determining unit, and a second certificate determining unit.
[0181] Optionally, the digital certificate issuing unit is used to issue digital certificates for the first component and the second component through a certificate authority; the first certificate determining unit is used to use the digital certificate of the first component as the first certificate, wherein the first certificate includes at least the component identifier, public key and certificate validity period of the first component; the second certificate determining unit is used to use the digital certificate of the second component as the second certificate, wherein the second certificate includes at least the component address and component identifier of the second component.
[0182] In one optional embodiment, the two-way authentication unit 601 includes: an encryption subunit, an encapsulation subunit, a first transmission subunit, a certificate status determination subunit, and a two-way security authentication subunit.
[0183] Optionally, the encryption subunit is used to encrypt the first certificate of the first component using a preset encryption algorithm to obtain a first encrypted value; the encapsulation subunit is used to encapsulate the first encrypted value to obtain a connection request of the first component, wherein the connection request includes at least the first encrypted value, a timestamp, and a random number generated by the first component; the first transmission subunit is used to transmit the connection request of the first component to the second component; the certificate status determination subunit is used to determine the certificate status of the first certificate based on the connection request through the second component, wherein the certificate status is a valid status or an invalid status; and the two-way security authentication subunit is used to perform two-way security authentication on the first component and the second component based on the certificate status of the first certificate.
[0184] In an optional embodiment, the two-way authentication unit 601 further includes: a second transmission subunit, a first verification subunit, a third transmission subunit, a second authentication verification subunit, and an authentication pass subunit.
[0185] Optionally, the second transmission subunit is configured to transmit the second certificate of the second component to the first component when the certificate status of the first certificate is valid; the first verification subunit is configured to perform signature verification on the second certificate based on the root certificate stored in the first component, wherein the root certificate includes at least the public key of the certificate authority; the third transmission subunit is configured to transmit the first certificate of the first component to the second component after the second certificate passes signature verification; the second authentication verification subunit is configured to perform signature verification on the first certificate based on the root certificate stored in the second component; and the authentication pass subunit is configured to determine that the first component and the second component have passed two-way security authentication after the first certificate passes signature verification.
[0186] In one optional embodiment, the anomaly detection unit 605 includes: a baseline feature determination subunit, a standard deviation acquisition subunit, a target deviation calculation subunit, and an anomaly detection subunit.
[0187] Optionally, the baseline feature determination subunit is used to determine N preset baseline features of the environmental monitoring equipment based on the equipment type of the equipment, wherein each preset baseline feature is used to characterize the average value of each historical behavior feature of the environmental monitoring equipment within a historical period; the standard deviation acquisition subunit is used to acquire the standard deviation corresponding to each of the N preset baseline features, wherein the standard deviation is used to characterize the fluctuation range of the historical behavior features of the environmental monitoring equipment within a historical period; the target deviation calculation subunit is used to calculate the target deviation of the environmental monitoring equipment based on the N behavior features of the environmental monitoring equipment, the N preset baseline features, and the standard deviation corresponding to each preset baseline feature; and the anomaly detection subunit is used to perform anomaly detection on the equipment behavior of the environmental monitoring equipment based on the target deviation.
[0188] In one optional embodiment, the anomaly detection subunit further includes: an inspection module, a first determination module, and a second determination module.
[0189] Optionally, the verification module is used to perform a target verification operation when the target deviation is greater than or equal to a preset deviation, wherein the target verification operation includes at least one of the following sub-operations: a first sub-operation for re-signing and verifying the random number generated by the second component based on the private key of the first component; a second sub-operation for re-checking the certificate status of the first certificate of the first component; a third sub-operation for checking the consistency between the component identifier of the first component and the component identifier in the first certificate; a first determination module is used to determine the behavior state of the environmental monitoring device as normal when the target deviation is less than the preset deviation or the target verification operation is successful; a second determination module is used to determine the behavior state of the environmental monitoring device as abnormal when the target verification operation fails.
[0190] In one optional embodiment, the device for detecting abnormal device behavior further includes an update unit and an alarm unit.
[0191] Optionally, the update unit is used to update the behavior baseline data of the environmental monitoring device based on N behavior features when the behavior status of the environmental monitoring device is normal. The behavior baseline data includes at least N preset baseline features and the standard deviation corresponding to each preset baseline feature. The alarm unit is used to cut off the encrypted channel, generate alarm information, and record the N behavior features of the environmental monitoring device through the log when the behavior status of the environmental monitoring device is abnormal.
[0192] As can be seen from the above, this application collects behavioral data of environmental devices through the first component and uses a preset encryption algorithm to perform two-way security authentication on the first and second components. By adding a security authentication mechanism and a zero-trust control mechanism, it achieves the purpose of improving the security of identity authentication and data transmission between the first and second components. This avoids the defects of traditional monitoring systems, such as easy impersonation of device identities, high data transmission security risks, and lack of dynamic monitoring of the behavior of connected devices. Thus, it achieves the technical effect of dynamic and continuous security authentication and secure data transmission between the first and second components, thereby solving the technical problem of low security in transmitting device behavior data when monitoring the behavior of environmental devices based on existing technologies.
[0193] It should be noted that the two-way authentication unit 601, channel establishment unit 602, feature extraction unit 603, feature transmission unit 604 and anomaly detection unit 605 mentioned above correspond to steps S101 to S105 in the method embodiment. The instances and application scenarios implemented by the above units and the corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment.
[0194] Example 3
[0195] Embodiments of this application can also provide an electronic device. Figure 7 This is a structural block diagram of an electronic device according to an embodiment of this application, such as... Figure 7 As shown, the electronic device includes: one or more ( Figure 7 (Only one is shown) Processor 702, memory 704, memory controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, network module and display.
[0196] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and devices in the embodiments of this application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the above-mentioned abnormal detection method for device behavior.
[0197] The memory may include high-speed random access memory (RAM), and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, which can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks (LANs), mobile communication networks, and combinations thereof.
[0198] The processor can access information and applications stored in the memory via a transmission device to execute the following steps: performing two-way security authentication on the first component and the second component based on a preset encryption algorithm, wherein the two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component; after the first component and the second component pass the two-way security authentication, establishing an encrypted channel between the first component and the second component; collecting behavioral data of the environmental monitoring device through the first component, extracting features from the behavioral data to obtain N behavioral features of the environmental monitoring device, where N is a positive integer; transmitting the N behavioral features to the second component through the encrypted channel; and performing anomaly detection on the device behavior of the environmental monitoring device based on the device type and the N behavioral features through the second component.
[0199] The processor can access information and applications stored in the memory via a transmission device to perform the following steps: issuing digital certificates for the first component and the second component through a certificate authority; using the digital certificate of the first component as the first certificate, wherein the first certificate includes at least the component identifier, public key, and certificate validity period of the first component; using the digital certificate of the second component as the second certificate, wherein the second certificate includes at least the component address and component identifier of the second component.
[0200] The processor can access information and applications stored in the memory via a transmission device to execute the following steps: encrypting the first certificate of the first component using a preset encryption algorithm to obtain a first encrypted value; encapsulating the first encrypted value to obtain a connection request for the first component, wherein the connection request includes at least the first encrypted value, a timestamp, and a random number generated by the first component; transmitting the connection request of the first component to the second component; determining the certificate status of the first certificate based on the connection request through the second component, wherein the certificate status is valid or invalid; and performing bidirectional security authentication between the first component and the second component based on the certificate status of the first certificate.
[0201] The processor can invoke information and applications stored in the memory via the transmission device to perform the following steps: If the certificate status of the first certificate is valid, transmit the second certificate of the second component to the first component; perform signature verification on the second certificate based on the root certificate stored in the first component, wherein the root certificate includes at least the public key of the certificate authority; after the second certificate passes signature verification, transmit the first certificate of the first component to the second component; perform signature verification on the first certificate based on the root certificate stored in the second component; after the first certificate passes signature verification, determine that the first component and the second component have passed two-way security authentication.
[0202] The processor can access information and applications stored in the memory via a transmission device to execute the following steps: Based on the device type of the environmental monitoring equipment, determine N preset baseline features of the environmental monitoring equipment, where each preset baseline feature is used to characterize the average value of each historical behavior feature of the environmental monitoring equipment within a historical period; obtain the standard deviation corresponding to each of the N preset baseline features, where the standard deviation is used to characterize the fluctuation range of the historical behavior features of the environmental monitoring equipment within a historical period; calculate the target deviation of the environmental monitoring equipment based on the N behavior features of the environmental monitoring equipment, the N preset baseline features, and the standard deviation corresponding to each preset baseline feature; and perform anomaly detection on the device behavior of the environmental monitoring equipment based on the target deviation.
[0203] The processor can invoke information and application programs stored in the memory via the transmission device to perform the following steps: If the target deviation is greater than or equal to a preset deviation, perform a target verification operation, wherein the target verification operation includes at least one of the following sub-operations: a first sub-operation for re-signing and verifying the random number generated by the second component based on the private key of the first component; a second sub-operation for re-checking the certificate status of the first certificate of the first component; a third sub-operation for checking the consistency between the component identifier of the first component and the component identifier in the first certificate; if the target deviation is less than the preset deviation / the target verification operation is successful, determine the behavior state of the environmental monitoring device as normal; if the target verification operation fails, determine the behavior state of the environmental monitoring device as abnormal.
[0204] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: when the behavior state of the environmental monitoring device is normal, update the behavior baseline data of the environmental monitoring device based on N behavior features, wherein the behavior baseline data includes at least N preset baseline features and the standard deviation corresponding to each preset baseline feature; when the behavior state of the environmental monitoring device is abnormal, cut off the encrypted channel, generate alarm information, and record the N behavior features of the environmental monitoring device through the log.
[0205] This application provides a scheme for detecting abnormal device behavior. It collects behavioral data from environmental monitoring devices using a first component and employs a pre-defined encryption algorithm to perform bidirectional security authentication between the first and second components. By adding a security authentication mechanism and a zero-trust control mechanism, it improves the security of identity authentication and data transmission between the first and second components. This avoids the shortcomings of traditional monitoring systems, such as easy impersonation of device identities, high data transmission security risks, and lack of dynamic monitoring of connected device behavior. It achieves dynamic and continuous secure authentication and secure data transmission between the first and second components, thus solving the technical problem of low security in transmitting device behavior data when monitoring the behavior of environmental monitoring devices using existing technologies.
[0206] Those skilled in the art will understand that Figure 7 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones, tablets, PDAs, mobile internet devices, PADs, and other terminal devices. Figure 7 This does not limit the structure of the aforementioned electronic device. For example, electronic devices may also include components that are more... Figure 7 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 7 The different configurations shown.
[0207] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0208] Example 4
[0209] Embodiments of this application may also provide a storage medium.
[0210] Optionally, in this embodiment of the application, the storage medium can be used to store the program code executed by the device behavior anomaly detection method provided in the above method embodiment.
[0211] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0212] This application also provides a computer program product, which, when executed on a data processing device, is suitable for performing steps of an anomaly detection method for device behavior.
[0213] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0214] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0215] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0216] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0217] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0218] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0219] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method of anomaly detection of device behavior, the method comprising: include: Based on a preset encryption algorithm, a two-way security authentication is performed on the first component and the second component, wherein the two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component; After the first component and the second component pass the two-way security authentication, an encrypted channel is established between the first component and the second component; The first component collects behavioral data of the environmental monitoring equipment, and the behavioral data is used to extract features to obtain N behavioral features of the environmental monitoring equipment, where N is a positive integer; The N behavioral features are transmitted to the second component through the encrypted channel; The second component is used to detect anomalies in the behavior of the environmental monitoring equipment based on its equipment type and N behavioral characteristics. The method for detecting anomalies in the behavior of a dynamic environmental monitoring device (VOID) based on its device type and N behavioral characteristics includes: determining N preset baseline features for the VOID based on its device type, where each preset baseline feature represents the average value of each historical behavioral characteristic of the VOID within a historical period; obtaining the standard deviation corresponding to each of the N preset baseline features, where the standard deviation represents the fluctuation range of the historical behavioral characteristics of the VOID within a historical period; calculating the target deviation of the VOID based on the N behavioral characteristics, the N preset baseline features, and the standard deviation corresponding to each preset baseline feature; and detecting anomalies in the behavior of the VOID based on the target deviation. The method for detecting anomalies in the behavior of the environmental monitoring device based on the target deviation includes: performing a target verification operation when the target deviation is greater than or equal to a preset deviation, wherein the target verification operation includes at least one of the following sub-operations: a first sub-operation for re-signing and verifying the random number generated by the second component based on the private key of the first component; a second sub-operation for re-checking the certificate status of the first certificate of the first component; a third sub-operation for checking the consistency between the component identifier of the first component and the component identifier in the first certificate; determining the behavior state of the environmental monitoring device as normal when the target deviation is less than the preset deviation or the target verification operation is successful; and determining the behavior state of the environmental monitoring device as abnormal when the target verification operation fails.
2. The device behavior abnormality detection method according to claim 1, characterized by, Before performing two-way security authentication on the first and second components based on a preset encryption algorithm, the method for detecting abnormal device behavior further includes: Digital certificates are issued for the first component and the second component through a certificate authority. The digital certificate of the first component is used as the first certificate, wherein the first certificate includes at least the component identifier, public key and certificate validity period of the first component; The digital certificate of the second component is used as the second certificate, wherein the second certificate includes at least the component address and component identifier of the second component.
3. The device behavior abnormality detection method according to claim 1, characterized by, Based on a preset encryption algorithm, two-way security authentication is performed on the first component and the second component, including: The first certificate of the first component is encrypted using the preset encryption algorithm to obtain the first encrypted value; The first encrypted value is encapsulated to obtain a connection request for the first component, wherein the connection request includes at least the first encrypted value, a timestamp, and a random number generated by the first component; The connection request from the first component is transmitted to the second component; The second component determines the certificate status of the first certificate based on the connection request, wherein the certificate status is either valid or invalid. Based on the certificate status of the first certificate, the two-way security authentication is performed on the first component and the second component.
4. The method for detecting abnormal equipment behavior according to claim 3, characterized in that, Based on the certificate status of the first certificate, the two-way security authentication is performed on the first component and the second component, including: If the certificate status of the first certificate is in the valid state, the second certificate of the second component is transmitted to the first component; Based on the root certificate stored in the first component, the second certificate is signed and verified, wherein the root certificate includes at least the public key of the certificate authority. After the second certificate passes signature verification, the first certificate of the first component is transmitted to the second component; Based on the root certificate stored in the second component, the first certificate is signed and verified; After the first certificate passes signature verification, it is determined that the first component and the second component have passed the two-way security authentication.
5. The method for detecting abnormal equipment behavior according to claim 1, characterized in that, After performing anomaly detection on the behavior of the dynamic environment equipment, the anomaly detection method further includes: When the behavior state of the environmental monitoring device is normal, the behavior baseline data of the environmental monitoring device is updated based on the N behavior features, wherein the behavior baseline data includes at least N preset baseline features and the standard deviation corresponding to each preset baseline feature; When the behavior of the environmental monitoring device is in an abnormal state, the encrypted channel is cut off, an alarm message is generated, and N behavioral characteristics of the environmental monitoring device are recorded in the log.
6. A device for detecting abnormal equipment behavior, characterized in that, include: A two-way authentication unit is used to perform two-way security authentication on a first component and a second component based on a preset encryption algorithm, wherein the two-way security authentication is used to verify the signatures of the digital certificates corresponding to the first component and the second component. A channel establishment unit is configured to establish an encrypted channel between the first component and the second component after the first component and the second component have passed the bidirectional security authentication. The feature extraction unit is used to collect behavioral data of the environmental equipment through the first component, extract features from the behavioral data, and obtain N behavioral features of the environmental equipment, where N is a positive integer; A feature transmission unit is used to transmit the N behavioral features to the second component through the encrypted channel; An anomaly detection unit is used to detect anomalies in the behavior of the environmental equipment based on the equipment type and N behavioral characteristics of the environmental equipment, using the second component. The anomaly detection unit includes: a baseline feature determination subunit, used to determine N preset baseline features of the environmental monitoring equipment based on the equipment type of the equipment, wherein each preset baseline feature is used to characterize the average value of each historical behavior feature of the environmental monitoring equipment within a historical period; a standard deviation acquisition subunit, used to acquire the standard deviation corresponding to each of the N preset baseline features, wherein the standard deviation is used to characterize the fluctuation range of the historical behavior features of the environmental monitoring equipment within a historical period; a target deviation calculation subunit, used to calculate the target deviation of the environmental monitoring equipment based on the N behavior features, the N preset baseline features, and the standard deviation corresponding to each preset baseline feature; and an anomaly detection subunit, used to perform anomaly detection on the equipment behavior of the environmental monitoring equipment based on the target deviation. The anomaly detection subunit includes: a verification module, configured to perform a target verification operation when the target deviation is greater than or equal to a preset deviation, wherein the target verification operation includes at least one of the following sub-operations: a first sub-operation, configured to re-verify the signature of the random number generated by the second component based on the private key of the first component; a second sub-operation, configured to re-detect the certificate status of the first certificate of the first component; a third sub-operation, configured to detect the consistency between the component identifier of the first component and the component identifier in the first certificate; a first determination module, configured to determine the behavior state of the environmental monitoring device as normal when the target deviation is less than the preset deviation or the target verification operation is successfully verified; and a second determination module, configured to determine the behavior state of the environmental monitoring device as abnormal when the target verification operation fails to verify.
7. A computer program product, characterized in that, The computer program product includes a computer program, wherein, when the computer program is executed, it controls the computer program product to perform the abnormal detection method of device behavior as described in any one of claims 1 to 5.
8. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the abnormal detection method of device behavior as described in any one of claims 1 to 5.