An internet of things security early warning linkage decision method

By constructing a risk elasticity field and a reversible causal graph, and combining it with a cross-domain dual graph neural network, the shortcomings of dynamic risk characterization and coordinated decision-making in IoT security early warning technology are solved, achieving highly accurate and self-optimizing security early warning and coordinated decision-making.

CN121792227BActive Publication Date: 2026-07-31ZHONGLANG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHONGLANG INFORMATION TECH CO LTD
Filing Date
2026-01-13
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing IoT security early warning technologies lack effective means for dynamic risk characterization and coordinated decision-making, resulting in delayed early warning results, high false alarm rates, and coordination strategies that rely on static rules and lack optimization capabilities, making it difficult to conduct comprehensive evaluations in complex attack scenarios.

Method used

By constructing a risk elasticity field, a risk state mapping space, and a reversible causal graph, and combining it with a cross-domain dual graph neural network, the security risks in the Internet of Things system are dynamically characterized and predicted, and the optimal security linkage action sequence is generated to achieve intelligent assessment and closed-loop optimization.

Benefits of technology

It improves the accuracy and foresight of security warnings, reduces the probability of false alarms and missed alarms, can accurately identify key handling paths in complex attack scenarios, avoids excessive or insufficient linkage, and forms a self-optimizing closed-loop protection mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792227B_ABST
    Figure CN121792227B_ABST
Patent Text Reader

Abstract

This invention discloses an IoT security early warning and linkage decision-making method, comprising: collecting multi-source security data, preprocessing and mapping assets, constructing asset nodes, and generating basic asset profiles; based on the profiles and historical events, generating anchor points and attenuation configurations, constructing a risk elasticity field, and generating risk impact information; constructing a risk state mapping space, forming a risk state trajectory, and extracting risk state description information; constructing a reversible causal graph, fusing the profiles and state descriptions, establishing positive causal relationships, and establishing reverse recovery relationships; extracting positive causal subgraphs, deducing risk state trajectories, combining the elasticity field to generate predicted states, and outputting early warnings and levels; generating candidate linkage sequences through reverse deduction, evaluating them using a dual graph neural network, and determining and executing the target sequence. This invention achieves predictive early warning and intelligent linkage decision-making for IoT security through risk elasticity modeling and causal deduction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) security technology, and in particular to an IoT security early warning and linkage decision-making method. Background Technology

[0002] With the rapid development of IoT technology, IoT terminal devices are widely used in smart cities, industrial internet, energy, transportation, and public safety scenarios. IoT systems typically consist of a large number of heterogeneous terminals, network communication facilities, and management platforms, continuously generating device operation data, communication data, and security log data during operation. To ensure the stable operation of IoT systems, existing technologies are gradually introducing security monitoring and early warning mechanisms. By detecting and analyzing security events, potential risks can be identified in advance, and corresponding security measures can be triggered when necessary, thereby reducing the impact of security events on business systems.

[0003] However, most existing IoT security early warning technologies are based on static rules, threshold judgments, or simple risk scoring models. Their risk assessment dimensions are relatively singular, typically focusing only on the severity or frequency of current security incidents, making it difficult to comprehensively characterize the dynamic risk tolerance of different assets under different operating conditions. Existing technologies provide rudimentary modeling of the risk propagation process, lacking effective characterization of risk propagation mechanisms in cyberspace, temporal evolution, and business scenarios, resulting in delayed early warning results or high false alarm rates. Existing early warning mechanisms primarily rely on single-point state judgments, lacking the ability to predict future risk evolution trends and failing to promptly detect impending high-impact security risks.

[0004] In terms of coordinated response, existing technologies typically separate security alerts from coordinated decision-making. Coordinated strategies often rely on pre-configured rules or human experience, lacking systematic evaluation and verification of the effects of coordinated actions, which can easily lead to under- or over-handling. Existing technologies struggle to combine and evaluate multiple coordinated actions in complex attack scenarios, failing to form optimal action sequences and lacking closed-loop optimization capabilities based on execution results. Current IoT security alerts and coordinated decision-making technologies still have significant shortcomings in dynamic risk characterization, risk propagation modeling, coordinated strategy evaluation, and closed-loop optimization.

[0005] Therefore, how to provide an IoT security early warning and linkage decision-making method is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0006] One objective of this invention is to propose a security early warning and linkage decision-making method for the Internet of Things (IoT). This invention dynamically characterizes and predicts security risks in IoT systems by constructing a risk elasticity field, a risk state mapping space, and a reversible causal graph. It utilizes a cross-domain dual graph neural network to intelligently evaluate and decide on security linkage actions. This invention comprehensively leverages IoT security monitoring, risk propagation modeling, causal inference, and graph neural network technologies to achieve accurate early warning of IoT asset risk evolution trends and verifiable evaluation of the effectiveness of linkage responses. It can automatically generate optimal security linkage action sequences and possesses advantages such as rich risk assessment dimensions, high early warning accuracy, strong linkage decision rationality, and support for closed-loop adaptive optimization.

[0007] An IoT security early warning and linkage decision-making method according to an embodiment of the present invention includes:

[0008] Collect multi-source security data from IoT terminal devices, network devices, security protection devices, and business systems; preprocess the multi-source security data; construct IoT asset nodes; and generate a corresponding basic asset profile for each IoT asset.

[0009] Based on asset profiles, IoT network topology, asset business load status, and historical security event data, a risk resilience field is constructed for each IoT asset, and risk impact information is generated based on real-time security event data.

[0010] Based on risk elasticity field and risk shock information, a risk state mapping space is constructed, and each IoT asset is mapped to the risk state mapping space to form a risk state trajectory. Risk state description information that characterizes the current risk evolution of the asset is extracted.

[0011] Construct a reversible causal graph, taking asset profile and risk status description information as input, and establish positive causal relationships and reverse recovery relationships in the reversible causal graph;

[0012] Based on positive causality, the risk state trajectory is deduced, and the risk elasticity field is combined to generate a predicted risk state. Based on the predicted risk state, IoT security early warning information is generated and the early warning level is determined.

[0013] Based on the reverse recovery relationship and early warning level, the current risk status is reverse-engineered to generate candidate safety linkage action sequences. The candidate safety linkage action sequences are evaluated using a cross-domain dual graph neural network, the target safety linkage action sequence is determined and executed, and the risk elasticity field, risk status mapping space and reversible causal graph are updated based on the safety data after linkage execution.

[0014] Optionally, the multi-source security data includes device operation data, command interaction data, and status change data generated by IoT assets; communication connection data, traffic characteristic data, and protocol interaction data generated by IoT networks; alarm event data, anomaly detection data, and vulnerability information data related to security protection; and business operation status data and operation and maintenance management data associated with IoT assets.

[0015] Optionally, the preprocessing of multi-source security data includes time synchronization processing, data deduplication processing, outlier removal processing, data format unification processing, and asset association mapping processing based on device identifiers, network identifiers, or certificate identifiers.

[0016] Optionally, the construction of IoT asset nodes, generating a corresponding basic asset profile for each IoT asset, includes:

[0017] Based on the unique device identifier, network identifier, or security credentials, asset ownership is identified from multi-source security data to determine IoT asset nodes;

[0018] Based on the device type, deployment location, network topology location, and security domain information associated with the IoT asset node, a structural attribute profile of the asset is generated.

[0019] Based on the operational behavior characteristics, security event history, and business relationships of the IoT asset within a preset time range, a profile of the asset's behavioral and security attributes is generated, forming the basic asset profile of the IoT asset.

[0020] Optionally, the step of constructing a risk resilience field for each IoT asset and generating risk impact information based on real-time security event data includes:

[0021] Extract asset type, deployment location, business criticality, exposure surface and handling records from asset basic profile and historical security incident data, establish an asset elasticity anchor point set for each IoT asset, and record the upper bound of tolerance, the upper bound of recovery time and the degradation trigger threshold for each anchor point to form an initial asset elasticity descriptor.

[0022] The system analyzes communication connection data and access control configurations in multi-source security data to determine asset connection relationships and security domain boundaries. It generates cross-domain impedance indexes based on isolation strength, access control strength, link bandwidth, and delay limits, and generates spatial propagation attenuation configurations.

[0023] Based on business operation status data and operation and maintenance management data, a time phase modulation profile is generated. The time phase modulation profile provides adjustment coefficients and switching thresholds for asset elasticity anchor points for working periods, peak periods and maintenance periods, respectively. The time phase modulation profile is combined with the initial asset elasticity description to obtain the time phase corrected asset elasticity descriptor.

[0024] Based on historical security incidents and the results of coordinated responses, the asset resilience descriptor and spatial propagation attenuation configuration are calibrated using counterfactual replay. The configuration parameters are corrected by comparing multiple response scenarios to generate the risk resilience field for each IoT asset.

[0025] The event intensity, attack stage, attack source identifier, and affected location are extracted from real-time security event data to generate risk impact information.

[0026] Optionally, the extraction of risk state description information characterizing the current risk evolution features of the asset includes:

[0027] Based on the risk elasticity field, risk shock information, spatial propagation attenuation configuration, temporal modulation archive and asset elasticity anchor set, a risk state mapping space is constructed. The risk state mapping space consists of elasticity response dimension, shock response dimension, propagation attenuation dimension and temporal dimension. According to the risk state evolution characteristics, state migration constraints and recovery path constraints, the region is divided to generate risk anchor grids determined by asset elasticity anchor set and spatial propagation attenuation configuration.

[0028] For each IoT asset, elastic response, impact intensity, propagation range and temporal location features are extracted from the risk elasticity field and risk impact information in discrete time series. The features are standardized and time-series organized, and the coordinates are aligned according to the risk anchor grid to obtain the initial coordinates.

[0029] A reference alignment set is constructed based on historical security incidents and joint response records. The reference alignment set is used to perform global alignment and offset correction on the initial coordinates to obtain the normalized coordinates of the asset at the current moment. The mapping rules used for alignment and correction are stored as fixed mapping rules.

[0030] At each discrete moment, feature extraction and coordinate alignment are repeated, and normalized coordinates are obtained according to fixed mapping rules. The normalized coordinates are connected in chronological order to form the risk state trajectory of the asset. When the entry into the recovery channel domain is detected, the unidirectional constraint of the recovery channel domain is applied to make the trajectory evolve monotonically in the recovery direction within the domain.

[0031] Risk state description information is generated based on the risk state trajectory. The risk state description information includes the current normalized coordinates, the directional features obtained from the difference between normalized coordinates at adjacent times, the velocity features obtained from the change in normalized coordinates per unit time, the curvature features obtained from the rate of change of adjacent directions, and the stability features obtained from the duration of the trajectory in each region.

[0032] Optionally, establishing positive causal relationships and reverse recovery relationships in the reversible causal graph includes:

[0033] Based on asset profiles, risk impact information, and risk status description information, a set of nodes for a reversible causal graph is constructed. The set of nodes includes event nodes, state nodes, and action nodes, and a corresponding state node is established for each IoT asset.

[0034] The risk status description information is combined with the corresponding asset basic profile as the node attribute information of the status node, the risk impact information is used as the node attribute information of the event node, and the preset linkage disposal behavior type, execution constraints and accessibility conditions are used as the node attribute information of the action node.

[0035] Based on the order of occurrence of historical security events, the evolution order of risk state trajectories, and the temporal correlation between events and states, positive causal relationships are established between event nodes and state nodes, and state transition causal relationships are established between state nodes. The corresponding impact intensity, triggering conditions, and effect delay are recorded for each positive causal relationship, forming a set of positive causal relationships.

[0036] Based on historical records of coordinated response, the risk status trajectory decline process, and the impact of response actions on changes in risk status, a reverse recovery relationship is established between action nodes and status nodes, and the corresponding recovery capability, recovery direction, and recovery constraints are recorded for each reverse recovery relationship.

[0037] The set of positive causal relationships and the set of negative recovery relationships are incorporated into the same reversible causal graph structure by setting a risk attraction domain identifier and a recovery channel identifier for each state node.

[0038] Optionally, the step of generating IoT security early warning information and determining the early warning level based on the predicted risk status includes:

[0039] Set the prediction time window and sampling step size, select the risk state description information at the current moment from the risk state trajectory, extract the positive causal subgraph associated with the risk state description information from the reversible causal graph, establish a two-level time series structure of event time axis and state time axis and a deduction queue for state update.

[0040] Forward inference is performed based on the stacking rules of trigger-propagation-dissipation of the positive causal subgraph. Candidate state transitions are generated according to the triggering conditions and action delays of the positive causal relationship. The influence of the risk elastic field and time phase modulation on the candidate state transitions is attenuated or amplified. The processed state update is written into the inference queue according to the sampling step size.

[0041] For each IoT asset, a risk energy budget table is established within the prediction time window. Budget values ​​are configured according to the sampling time and connection location. During the simulation, budget deduction is performed on each candidate state transition. Paths that run out of budget are immediately stopped and marked as pruned paths. Candidate state transitions that exceed the budget but meet the mandatory triggering conditions are marked as mandatory constraint transitions.

[0042] The state update obtained from the deduction is mapped to the risk state mapping space hourly, the coordinates are aligned according to the risk anchor grid and the anchor point reprojection is performed, and the normalized coordinates at each time point are connected in time order to form the predicted risk state trajectory.

[0043] The predicted risk state trajectory is compared with the risk elastic field hourly to mark the overload location and overload period. The overload duration and overload magnitude are summarized to generate the predicted risk state. Based on the predicted risk state, IoT security early warning information is generated and the early warning level is determined.

[0044] Optionally, the step of evaluating candidate security linkage action sequences using a cross-domain dual graph neural network, determining the target security linkage action sequence, and executing it includes:

[0045] Obtain the warning level and the current risk status description information of the corresponding IoT assets, extract the reverse recovery relationship associated with the assets from the reversible causal graph, form a reverse recovery subgraph, and obtain a set of executable safety linkage actions based on the device online status, interface availability and execution window.

[0046] Based on the warning level, the linkage depth and execution time limit are set. Under the constraints, the set of safety linkage actions is combined in a restricted manner based on the reverse recovery relationship to generate a candidate safety linkage action sequence that satisfies the action dependency relationship and does not violate the action conflict relationship.

[0047] Using the current risk state description information as the initial state, each candidate safety linkage action sequence is reverse-engineered in the reverse recovery subgraph according to the action order, and the risk state change process obtained by the deduction is mapped to the risk state mapping space to form the corresponding candidate recovery trajectory.

[0048] A cross-domain dual graph neural network is constructed to evaluate candidate security linkage action sequences. The cross-domain dual graph neural network consists of three sequentially connected layers, wherein:

[0049] The risk propagation perception layer receives information on predicted risk state trajectories and positive causal relationships, and generates risk propagation representations.

[0050] The action recovery modeling layer receives candidate safety linkage action sequences and recovery propagation paths in the reverse recovery subgraph, and generates action recovery representations.

[0051] The third layer is the cross-domain dual fusion layer, which aligns and fuses the risk propagation representation and the action recovery representation. During the fusion process, recovery priority constraints and business impact constraints are introduced, and the risk reduction effect, recovery efficiency, business impact degree, execution cost and execution success probability corresponding to each candidate security linkage action sequence are output.

[0052] Based on the evaluation results, the candidate safety linkage action sequences are sorted, and the safety linkage action sequence with the best overall effect is selected as the target safety linkage action sequence and executed. Safety data after linkage execution is collected, and the risk elasticity field, risk state mapping space and reversible causal graph are updated based on the safety data.

[0053] The beneficial effects of this invention are:

[0054] The IoT security early warning and linkage decision-making method proposed in this invention can characterize security risks in a multi-dimensional and dynamic way in the complex operating environment of IoT, breaking through the limitations of existing technologies that only rely on static thresholds or single risk scores for early warning. This invention constructs a risk elasticity field and a risk state mapping space to uniformly model the risk tolerance of different IoT assets under different operating stages and security situations, achieving continuous expression and trend characterization of risk states. This improves the accuracy and foresight of security early warnings and effectively reduces the probability of false alarms and missed alarms.

[0055] This invention introduces a reversible causal graph to uniformly model the relationship between security events, asset status, and coordinated actions, making risk propagation paths and coordinated response effects predictable and verifiable. Based on this, it uses forward causal relationships to predict the risk evolution process and reverse recovery relationships to inversely evaluate the recovery capability of coordinated actions. This transforms security coordinated decision-making from a traditional rule-driven approach to an intelligent decision-making approach based on causal inference, enabling accurate identification of critical response paths in complex attack scenarios and avoiding over-coordination or under-response.

[0056] This invention utilizes a cross-domain dual graph neural network to jointly model risk propagation and action recovery representations, enabling comprehensive evaluation of multiple candidate linkage action sequences. Furthermore, it continuously updates model parameters based on linkage execution results, forming a complete closed-loop optimization mechanism. This technical solution not only automatically generates optimal security linkage action sequences but also continuously adjusts and optimizes itself as the system operates and security situation changes, enhancing the intelligence, adaptability, and overall protection effectiveness of IoT security early warning and linkage decision-making. Attached Figure Description

[0057] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0058] Figure 1 This is a flowchart of an IoT security early warning and linkage decision-making method proposed in this invention;

[0059] Figure 2 This is a schematic diagram illustrating the construction of a risk state mapping space and the formation of an IoT asset risk state trajectory for an IoT security early warning and linkage decision-making method proposed in this invention. Detailed Implementation

[0060] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0061] refer to Figure 1 and Figure 2 An IoT security early warning and linkage decision-making method includes:

[0062] Collect multi-source security data from IoT terminal devices, network devices, security protection devices, and business systems; preprocess the multi-source security data; construct IoT asset nodes; and generate a corresponding basic asset profile for each IoT asset.

[0063] Based on asset profiles, IoT network topology, asset business load status, and historical security event data, a risk resilience field is constructed for each IoT asset, and risk impact information is generated based on real-time security event data.

[0064] Based on risk elasticity field and risk shock information, a risk state mapping space is constructed, and each IoT asset is mapped to the risk state mapping space to form a risk state trajectory. Risk state description information that characterizes the current risk evolution of the asset is extracted.

[0065] Construct a reversible causal graph, taking asset profile and risk status description information as input, and establish positive causal relationships and reverse recovery relationships in the reversible causal graph;

[0066] Based on positive causality, the risk state trajectory is deduced, and the risk elasticity field is combined to generate a predicted risk state. Based on the predicted risk state, IoT security early warning information is generated and the early warning level is determined.

[0067] Based on the reverse recovery relationship and early warning level, the current risk status is reverse-engineered to generate candidate safety linkage action sequences. The candidate safety linkage action sequences are evaluated using a cross-domain dual graph neural network, the target safety linkage action sequence is determined and executed, and the risk elasticity field, risk status mapping space and reversible causal graph are updated based on the safety data after linkage execution.

[0068] In this embodiment, the multi-source security data includes device operation data, command interaction data, and status change data generated by IoT assets; communication connection data, traffic characteristic data, and protocol interaction data generated by IoT networks; alarm event data, anomaly detection data, and vulnerability information data related to security protection; and business operation status data and operation and maintenance management data associated with IoT assets.

[0069] In this embodiment, the preprocessing of multi-source security data includes time synchronization processing, data deduplication processing, outlier removal processing, data format unification processing, and asset association mapping processing based on device identifier, network identifier, or certificate identifier.

[0070] In this embodiment, the construction of IoT asset nodes, which generates a corresponding basic asset profile for each IoT asset, includes:

[0071] Based on the unique device identifier, network identifier, or security credentials, asset ownership is identified from multi-source security data to determine IoT asset nodes;

[0072] Based on the device type, deployment location, network topology location, and security domain information associated with the IoT asset node, a structural attribute profile of the asset is generated.

[0073] Based on the operational behavior characteristics, security event history, and business relationships of the IoT asset within a preset time range, a profile of the asset's behavioral and security attributes is generated, forming the basic asset profile of the IoT asset.

[0074] In this embodiment, the step of constructing a risk resilience field for each IoT asset and generating risk impact information based on real-time security event data includes:

[0075] Extract asset type, deployment location, business criticality, exposure surface and handling records from asset basic profile and historical security incident data, establish an asset elasticity anchor point set for each IoT asset, and record the upper bound of tolerance, the upper bound of recovery time and the degradation trigger threshold for each anchor point to form an initial asset elasticity descriptor.

[0076] The system analyzes communication connection data and access control configurations from multi-source security data to determine asset connection relationships and security domain boundaries. Based on isolation strength, access control strength, link bandwidth, and delay limits, it generates a cross-domain impedance index and a spatial propagation attenuation configuration.

[0077] Isolation strength refers to the isolation capability achieved between IoT assets and other assets through network partitioning, VLANs, physical isolation, and perimeter firewalls.

[0078] Access control strength refers to the strictness of access control policies between IoT assets and between assets and external entities;

[0079] Link bandwidth and latency limits refer to the maximum data transmission rate of the actual communication link between assets, and latency limits refer to the maximum value of the round-trip delay.

[0080] Based on business operation status data and operation and maintenance management data, a time phase modulation profile is generated. The time phase modulation profile provides adjustment coefficients and switching thresholds for asset elasticity anchor points for working periods, peak periods and maintenance periods, respectively. The time phase modulation profile is combined with the initial asset elasticity description to obtain the time phase corrected asset elasticity descriptor.

[0081] Based on historical security incidents and coordinated response results, counterfactual replay calibration is performed on the asset resilience descriptor and spatial propagation attenuation configuration. Configuration parameters are corrected through comparison of multiple response scenarios to generate a risk resilience field for each IoT asset. Specifically, the counterfactual replay calibration of the asset resilience descriptor and spatial propagation attenuation configuration involves:

[0082] While maintaining consistency in the timing, sequence, and location of historical security incidents, construct event replay scenarios where no coordinated response was implemented, and generate corresponding risk status evolution records;

[0083] Based on the event replay scenarios where no coordinated action was taken, single coordinated action scenarios and multi-coordinated action combination scenarios are constructed respectively, and risk status evolution records are generated for each scenario.

[0084] The risk status evolution records under the non-implementation linkage response scenario and each linkage response scenario are compared. Based on the differences in the spatial range, time span and magnitude of change of the risk status, the parameters in the asset elasticity descriptor and spatial propagation attenuation configuration are modified.

[0085] The event intensity, attack stage, attack source identifier, and affected location are extracted from real-time security event data to generate risk impact information.

[0086] In this embodiment, the extraction of risk status description information characterizing the current risk evolution characteristics of an asset includes:

[0087] Based on the risk elasticity field, risk shock information, spatial propagation attenuation configuration, temporal modulation archive and asset elasticity anchor set, a risk state mapping space is constructed. The risk state mapping space consists of elasticity response dimension, shock response dimension, propagation attenuation dimension and temporal dimension. According to the risk state evolution characteristics, state migration constraints and recovery path constraints, the region is divided to generate risk anchor grids determined by asset elasticity anchor set and spatial propagation attenuation configuration.

[0088] For each IoT asset, elastic response, impact intensity, propagation range and temporal location features are extracted from the risk elasticity field and risk impact information in discrete time series. The features are standardized and time-series organized, and the coordinates are aligned according to the risk anchor grid to obtain the initial coordinates.

[0089] A reference alignment set is constructed based on historical security incidents and joint response records. The reference alignment set is used to perform global alignment and offset correction on the initial coordinates to obtain the normalized coordinates of the asset at the current moment. The mapping rules used for alignment and correction are stored as fixed mapping rules.

[0090] Feature extraction and coordinate alignment are repeated at each discrete time point. Normalized coordinates are obtained according to a fixed mapping rule. The normalized coordinates are connected in chronological order to form the risk state trajectory of the asset. When entering the recovery channel domain is detected, a unidirectional constraint of the recovery channel domain is applied to ensure that the trajectory evolves monotonically in the recovery direction within the domain. The fixed mapping rule is as follows:

[0091] In the risk state mapping space, the anchor center determined by the asset elasticity anchor point set is used as the coordinate reference point, and the feature vectors extracted at each discrete time are subjected to consistent coordinate translation and scale normalization.

[0092] Between consecutive discrete moments, the order, weight, and scale parameters of each dimension of the risk state mapping space remain unchanged, and the normalized coordinates are mapped consistently.

[0093] When the risk state is located within the recovery channel domain, a directional constraint is applied to the mapped normalized coordinates, limiting the risk state to only update its position along a preset recovery direction within the recovery channel domain;

[0094] Risk state description information is generated based on the risk state trajectory. The risk state description information includes the current normalized coordinates, the directional features obtained from the difference between normalized coordinates at adjacent times, the velocity features obtained from the change in normalized coordinates per unit time, the curvature features obtained from the rate of change of adjacent directions, and the stability features obtained from the duration of the trajectory in each region.

[0095] In this embodiment, establishing positive causal relationships and reverse recovery relationships in the reversible causal graph includes:

[0096] Based on asset profiles, risk impact information, and risk status description information, a set of nodes for a reversible causal graph is constructed. The set of nodes includes event nodes, state nodes, and action nodes, and a corresponding state node is established for each IoT asset.

[0097] The risk status description information is combined with the corresponding asset basic profile as the node attribute information of the status node, the risk impact information is used as the node attribute information of the event node, and the preset linkage response behavior types, execution constraints and accessibility conditions are used as the node attribute information of the action node. The preset linkage response behavior types include access control adjustment type, communication restriction type and asset status control type.

[0098] Based on the order of occurrence of historical security events, the evolution order of risk state trajectories, and the temporal correlation between events and states, positive causal relationships are established between event nodes and state nodes, and state transition causal relationships are established between state nodes. The corresponding impact intensity, triggering conditions, and effect delay are recorded for each positive causal relationship, forming a set of positive causal relationships.

[0099] Based on historical records of coordinated response, the risk status trajectory decline process, and the impact of response actions on changes in risk status, a reverse recovery relationship is established between action nodes and status nodes, and the corresponding recovery capability, recovery direction, and recovery constraints are recorded for each reverse recovery relationship.

[0100] The set of positive causal relationships and the set of negative recovery relationships are incorporated into the same reversible causal graph structure by setting a risk attraction domain identifier and a recovery channel identifier for each state node.

[0101] In this embodiment, the step of generating IoT security early warning information and determining the early warning level based on the predicted risk status includes:

[0102] Set the prediction time window and sampling step size, select the risk state description information at the current moment from the risk state trajectory, extract the positive causal subgraph associated with the risk state description information from the reversible causal graph, establish a two-level time series structure of event time axis and state time axis and a deduction queue for state update.

[0103] Forward inference is performed based on the stacking rules of trigger-propagation-dissipation of the positive causal subgraph. Candidate state transitions are generated according to the triggering conditions and action delays of the positive causal relationship. The influence of the risk elastic field and time phase modulation on the candidate state transitions is attenuated or amplified. The processed state update is written into the inference queue according to the sampling step size.

[0104] For each IoT asset, a risk energy budget table is established within the prediction time window. Budget values ​​are configured according to the sampling time and connection location. During the simulation, budget deduction is performed on each candidate state transition. Paths that run out of budget are immediately stopped and marked as pruned paths. Candidate state transitions that exceed the budget but meet the mandatory triggering conditions are marked as mandatory constraint transitions.

[0105] The derived state updates are mapped hourly to the risk state mapping space, coordinates are aligned according to risk anchor grids, and anchor point reprojection is performed. The normalized coordinates at each time step are connected in chronological order to form the predicted risk state trajectory. Specifically, the coordinate alignment and anchor point reprojection according to risk anchor grids are performed as follows:

[0106] Based on the asset elasticity anchor set, the corresponding risk anchor grid is determined in the risk status mapping space, and the status update at each time point is mapped to the coordinate range of the corresponding risk anchor grid.

[0107] When mapped to the same risk anchor, the updated coordinate values ​​are reprojected to the standard reference position or reference range of the risk anchor.

[0108] When the state update crosses adjacent risk anchor cells, the coordinates are continuously adjusted according to the adjacency relationship of the risk anchor cells so that the reprojected coordinates remain within the discrete spatial structure defined by the risk anchor cells.

[0109] The predicted risk state trajectory is compared with the risk elastic field hourly to mark the overload location and overload period. The overload duration and overload magnitude are summarized to generate the predicted risk state. Based on the predicted risk state, IoT security early warning information is generated and the early warning level is determined.

[0110] In this embodiment, the step of evaluating candidate security linkage action sequences using a cross-domain dual graph neural network, determining the target security linkage action sequence, and executing it includes:

[0111] Obtain the warning level and the current risk status description information of the corresponding IoT assets, extract the reverse recovery relationship associated with the assets from the reversible causal graph, form a reverse recovery subgraph, and obtain a set of executable safety linkage actions based on the device online status, interface availability and execution window.

[0112] Based on the warning level, the linkage depth and execution time limit are set. Under the constraints, the set of safety linkage actions is combined in a restricted manner based on the reverse recovery relationship to generate a candidate safety linkage action sequence that satisfies the action dependency relationship and does not violate the action conflict relationship.

[0113] Using the current risk state description information as the initial state, each candidate safety linkage action sequence is reverse-engineered in the reverse recovery subgraph according to the action order, and the risk state change process obtained by the deduction is mapped to the risk state mapping space to form the corresponding candidate recovery trajectory.

[0114] A cross-domain dual graph neural network is constructed to evaluate candidate security linkage action sequences. The cross-domain dual graph neural network consists of three sequentially connected layers, wherein:

[0115] The risk propagation perception layer receives information on predicted risk state trajectories and positive causal relationships, and generates a risk propagation representation. Specifically, the generation of this risk propagation representation involves:

[0116] Based on the predicted risk state trajectory, the risk state change sequence at each discrete moment is extracted, and the risk propagation time series features are formed in chronological order.

[0117] Based on positive causal relationship information, the propagation path and corresponding propagation order of risk between asset nodes are determined, and the propagation path is associated with the risk propagation time sequence characteristics;

[0118] Based on the magnitude and duration of the risk’s state changes under different propagation paths and sequences, the risk propagation time sequence characteristics are aggregated to form a risk propagation characterization that represents the scope, intensity, and speed of risk propagation.

[0119] The action recovery modeling layer receives candidate safety linkage action sequences and recovery propagation paths in the reverse recovery subgraph, and generates action recovery representations. Specifically, the generation of action recovery representations includes:

[0120] According to the execution order of each action in the candidate safety linkage action sequence, extract the corresponding action type, target object and execution constraint information, and form action sequence features;

[0121] Based on the reverse recovery subgraph, the recovery propagation path and propagation order of each action between asset nodes are determined, and the recovery propagation path is associated with the temporal characteristics of the action.

[0122] Based on the magnitude of risk status changes, recovery duration, and path coverage in each recovery propagation path, the action timing features are aggregated to form an action recovery representation that characterizes the recovery range, recovery intensity, and recovery speed.

[0123] The third layer is the cross-domain dual fusion layer, which aligns and fuses the risk propagation representation and the action recovery representation. During the fusion process, recovery priority constraints and business impact constraints are introduced. The layer outputs the risk reduction effect, recovery efficiency, business impact degree, execution cost, and probability of successful execution for each candidate security linkage action sequence.

[0124] The recovery priority constraint is based on the business criticality, risk status change magnitude, and recovery channel position of each asset node in the recovery propagation path corresponding to the candidate security linkage action sequence. This constraint limits the recovery order so that nodes located at critical nodes or in high-risk evolution stages in the recovery propagation path receive higher processing weights during the fusion process.

[0125] Business impact constraints are based on the business type, business continuity requirements, and historical business impact records associated with the asset nodes involved in the candidate security linkage action sequence. These constraints limit the scope, duration, and degree of business interruption that may be caused during the execution of the action. Furthermore, they constrain the recovery representation of actions that exceed the limits during the fusion process.

[0126] Based on the evaluation results, the candidate safety linkage action sequences are sorted, and the safety linkage action sequence with the best overall effect is selected as the target safety linkage action sequence and executed. Safety data after linkage execution is collected, and the risk elasticity field, risk state mapping space and reversible causal graph are updated based on the safety data.

[0127] Example 1:

[0128] To verify the feasibility of this invention in practice, it was applied to a smart park covering an area of ​​approximately 3.2 square kilometers. The park includes office buildings, research buildings, underground parking, and public supporting areas, and is equipped with approximately 7,500 IoT devices, including security cameras, access control terminals, environmental monitoring sensors, intelligent lighting controllers, and energy consumption data collection terminals. The park network adopts a zoned and domained architecture, with different business areas logically isolated through access control policies. During daily operation, it continuously generates device operation data, communication connection data, security log data, and maintenance management data.

[0129] In the park's existing security system, security alerts mainly rely on fixed rules and thresholds to trigger alarms for single-point anomalies, with maintenance personnel manually determining whether coordinated response measures are necessary. This approach has two prominent problems in actual operation: first, while the number of alarms is large, most are caused by short-term anomalies or business fluctuations, making manual screening costly; second, as risks accumulate across multiple devices and areas, the system struggles to identify risk evolution trends in a timely manner, leading to delayed coordinated responses and potential security risks.

[0130] In this embodiment, the IoT security early warning and linkage decision-making method proposed in this invention is introduced and deployed. The system first collects multi-source security data from IoT-related systems within the park, preprocesses the collected data and associates it with assets, constructs asset nodes for all IoT assets within the park, and generates a basic asset profile including device type, deployment location, communication characteristics, and historical security records. Through this basic asset profile, the system can distinguish the differences in business importance and security sensitivity among different assets.

[0131] Based on historical security incident data and operation and maintenance records, the system constructs a risk resilience field for each type of IoT asset within the park. This risk resilience field comprehensively reflects the asset's ability to withstand risk shocks under different operating conditions, and uses spatial propagation attenuation configuration to reflect the attenuation characteristics of risk along the communication connection path. During operation, the system generates risk shock information in real time and inputs the risk resilience field and risk shock information into a risk state mapping space to map and track the current risk state of each asset, forming a continuous risk state trajectory.

[0132] During a real-world operation, multiple cameras in the underground parking area of ​​the park experienced a sudden increase in abnormal access control requests within a short period. Traditional systems generated multiple low-to-medium level alarms for each individual device but failed to trigger coordinated action. This invention's system, through a risk state mapping space, discovered that the risk state trajectories of multiple cameras in the area exhibited a consistent evolution trend within the same time window. Furthermore, a reversible causal graph identified a positive causal relationship between this abnormal behavior and an adjustment to a specific access control policy configuration. Based on this positive causal relationship, the system extrapolated the risk state trajectories and predicted that without intervention, the abnormal behavior could spread to adjacent network areas within approximately 20 minutes.

[0133] Based on the above prediction results, the system generates corresponding security warnings and determines the warning level. Based on the reverse recovery relationship in the reversible causal graph, it performs reverse deduction of the current risk state and automatically generates multiple sets of candidate security linkage action sequences. The system uses a cross-domain dual graph neural network to evaluate the candidate action sequences, comprehensively considering the risk reduction effect, the scope of business impact, and execution costs. It selects the set of linkage action sequences with the least impact on parking lot operations and executes them automatically, including temporarily tightening access control policies and restricting abnormal communication connections.

[0134] Following the coordinated execution, the system continuously collected execution result data and updated the risk elasticity field, risk state mapping space, and reversible causal graph. Statistical results show that the time from the first occurrence of the anomaly to the completion of the coordinated response for this security incident was approximately 4.5 minutes, while before the deployment of the method of this invention, the average manual response time for similar incidents was approximately 11 minutes. The coordinated execution did not significantly impact normal parking lot operations, and the operating status of the relevant equipment returned to normal within 6 minutes.

[0135] Table 1. Comparative Statistics of IoT Security Operation Effects in Smart Parks

[0136]

[0137] As can be seen from the data comparison in Table 1, with the number of IoT terminals remaining constant, the overall safety operation of the park has significantly improved after adopting this invention. Firstly, in terms of the number of security alarms, the average daily number of security alarms decreased from 420 to 310, a reduction of approximately 26%, while the false alarm rate decreased from 28% to 19%. This indicates that this invention, by constructing a risk elasticity field and a risk state mapping space, provides more refined and trend-based modeling of asset risks, effectively filtering out short-term fluctuations and low-value anomalies.

[0138] Regarding early warning and response efficiency, the average early warning response time was reduced from 2.6 minutes to 1.4 minutes after adopting this invention, and the average coordinated response completion time was reduced from 11 minutes to 4.5 minutes, resulting in a significant improvement in overall response timeliness. This change demonstrates that this invention, based on a reversible causal graph, performs forward and backward extrapolation of risk states, enabling the system to generate early warnings before risks fully manifest and automatically assess the effectiveness of coordinated actions, thereby reducing manual intervention and waiting time, and achieving more timely safety responses.

[0139] From the perspectives of linkage effectiveness and business impact, the automatic linkage triggering rate increased from 22% to 61%, the linkage handling success rate increased from 88% to 94%, and the average business impact time decreased from 2.3 minutes to 0.9 minutes. This indicates that while improving automated handling capabilities, the present invention did not amplify the negative impact on business systems. Instead, by comprehensively evaluating candidate linkage action sequences through a cross-domain dual graph neural network, it prioritizes linkage schemes with significant risk reduction effects and minimal business impact, achieving a better balance between efficiency and stability in IoT security protection.

[0140] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. An Internet of Things security early warning linkage decision method, characterized in that, include: Collect multi-source security data from IoT terminal devices, network devices, security protection devices, and business systems; preprocess the multi-source security data; construct IoT asset nodes; and generate a corresponding basic asset profile for each IoT asset. Based on asset profiles, IoT network topology, asset business load status, and historical security event data, a risk resilience field is constructed for each IoT asset, and risk impact information is generated based on real-time security event data. Based on risk elasticity field and risk shock information, a risk state mapping space is constructed, and each IoT asset is mapped to the risk state mapping space to form a risk state trajectory. Risk state description information that characterizes the current risk evolution of the asset is extracted. Construct a reversible causal graph, taking asset profile and risk status description information as input, and establish positive causal relationships and reverse recovery relationships in the reversible causal graph; Based on positive causality, the risk state trajectory is deduced, and the risk elasticity field is combined to generate a predicted risk state. Based on the predicted risk state, IoT security early warning information is generated and the early warning level is determined. Based on the reverse recovery relationship and early warning level, the current risk status is reversed to generate candidate safety linkage action sequences. The candidate safety linkage action sequences are evaluated using a cross-domain dual graph neural network, the target safety linkage action sequence is determined and executed, and the risk elasticity field, risk status mapping space and reversible causal graph are updated based on the safety data after linkage execution. The establishment of positive causal relationships and reverse recovery relationships in a reversible causal graph includes: Based on asset profiles, risk impact information, and risk status description information, a set of nodes for a reversible causal graph is constructed. The set of nodes includes event nodes, state nodes, and action nodes, and a corresponding state node is established for each IoT asset. The risk status description information is combined with the corresponding asset basic profile as the node attribute information of the status node, the risk impact information is used as the node attribute information of the event node, and the preset linkage disposal behavior type, execution constraints and accessibility conditions are used as the node attribute information of the action node. Based on the order of occurrence of historical security events, the evolution order of risk state trajectories, and the temporal correlation between events and states, positive causal relationships are established between event nodes and state nodes, and state transition causal relationships are established between state nodes. The corresponding impact intensity, triggering conditions, and effect delay are recorded for each positive causal relationship, forming a set of positive causal relationships. Based on historical records of coordinated response, the risk status trajectory decline process, and the impact of response actions on changes in risk status, a reverse recovery relationship is established between action nodes and status nodes, and the corresponding recovery capability, recovery direction, and recovery constraints are recorded for each reverse recovery relationship. The set of positive causal relationships and the set of negative recovery relationships are incorporated into the same reversible causal graph structure by setting a risk attraction domain identifier and a recovery channel identifier for each state node.

2. The IoT security early warning and linkage decision-making method according to claim 1, characterized in that, The multi-source security data includes device operation data, command interaction data, and status change data generated by IoT assets; communication connection data, traffic characteristic data, and protocol interaction data generated by IoT networks; alarm event data, anomaly detection data, and vulnerability information data related to security protection; and business operation status data and operation and maintenance management data associated with IoT assets. 3.The IoT security early warning linkage decision method of claim 1, characterized in that, The preprocessing of multi-source security data includes time synchronization, deduplication, outlier removal, data format standardization, and asset association mapping based on device identifiers, network identifiers, or certificate identifiers.

4. The Internet of Things security early warning linkage decision method according to claim 1, characterized in that, The construction of IoT asset nodes generates a corresponding basic asset profile for each IoT asset, including: Based on the unique device identifier, network identifier, or security credentials, asset ownership is identified from multi-source security data to determine IoT asset nodes; Based on the device type, deployment location, network topology location, and security domain information associated with the IoT asset node, a structural attribute profile of the asset is generated. Based on the operational behavior characteristics, security event history, and business relationships of the IoT asset within a preset time range, a profile of the asset's behavioral and security attributes is generated, forming the basic asset profile of the IoT asset.

5. The Internet of Things security early warning linkage decision method according to claim 1, characterized in that, The process of constructing a risk resilience field for each IoT asset and generating risk impact information based on real-time security event data includes: Extract asset type, deployment location, business criticality, exposure surface and handling records from asset basic profile and historical security incident data, establish an asset elasticity anchor point set for each IoT asset, and record the upper bound of tolerance, the upper bound of recovery time and the degradation trigger threshold for each anchor point to form an initial asset elasticity descriptor. The system analyzes communication connection data and access control configurations in multi-source security data to determine asset connection relationships and security domain boundaries. It generates cross-domain impedance indexes based on isolation strength, access control strength, link bandwidth, and delay limits, and generates spatial propagation attenuation configurations. Based on business operation status data and operation and maintenance management data, a time phase modulation profile is generated. The time phase modulation profile provides adjustment coefficients and switching thresholds for asset elasticity anchor points for working periods, peak periods and maintenance periods, respectively. The time phase modulation profile is combined with the initial asset elasticity description to obtain the time phase corrected asset elasticity descriptor. Based on historical security incidents and the results of coordinated responses, the asset resilience descriptor and spatial propagation attenuation configuration are calibrated using counterfactual replay. The configuration parameters are corrected by comparing multiple response scenarios to generate the risk resilience field for each IoT asset. The event intensity, attack stage, attack source identifier, and affected location are extracted from real-time security event data to generate risk impact information.

6. The Internet of Things security early warning linkage decision method according to claim 1, characterized in that, The extraction of risk status description information characterizing the current risk evolution of assets includes: Based on the risk elasticity field, risk shock information, spatial propagation attenuation configuration, temporal modulation archive and asset elasticity anchor set, a risk state mapping space is constructed. The risk state mapping space consists of elasticity response dimension, shock response dimension, propagation attenuation dimension and temporal dimension. According to the risk state evolution characteristics, state migration constraints and recovery path constraints, the region is divided to generate risk anchor grids determined by asset elasticity anchor set and spatial propagation attenuation configuration. For each IoT asset, elastic response, impact intensity, propagation range and temporal location features are extracted from the risk elasticity field and risk impact information in discrete time series. The features are standardized and time-series organized, and the coordinates are aligned according to the risk anchor grid to obtain the initial coordinates. A reference alignment set is constructed based on historical security incidents and joint response records. The reference alignment set is used to perform global alignment and offset correction on the initial coordinates to obtain the normalized coordinates of the asset at the current moment. The mapping rules used for alignment and correction are stored as fixed mapping rules. At each discrete moment, feature extraction and coordinate alignment are repeated, and normalized coordinates are obtained according to fixed mapping rules. The normalized coordinates are connected in chronological order to form the risk state trajectory of the asset. When the entry into the recovery channel domain is detected, the unidirectional constraint of the recovery channel domain is applied to make the trajectory evolve monotonically in the recovery direction within the domain. Risk state description information is generated based on the risk state trajectory. The risk state description information includes the current normalized coordinates, the directional features obtained from the difference between normalized coordinates at adjacent times, the velocity features obtained from the change in normalized coordinates per unit time, the curvature features obtained from the rate of change of adjacent directions, and the stability features obtained from the duration of the trajectory in each region.

7. The IoT security early warning and linkage decision-making method according to claim 1, characterized in that, The process of generating IoT security early warning information and determining the early warning level based on the predicted risk status includes: Set the prediction time window and sampling step size, select the risk state description information at the current moment from the risk state trajectory, extract the positive causal subgraph associated with the risk state description information from the reversible causal graph, establish a two-level time series structure of event time axis and state time axis and a deduction queue for state update. Forward inference is performed based on the stacking rules of trigger-propagation-dissipation of the positive causal subgraph. Candidate state transitions are generated according to the triggering conditions and action delays of the positive causal relationship. The influence of the risk elastic field and time phase modulation on the candidate state transitions is attenuated or amplified. The processed state update is written into the inference queue according to the sampling step size. For each IoT asset, a risk energy budget table is established within the prediction time window. Budget values ​​are configured according to the sampling time and connection location. During the simulation, budget deduction is performed on each candidate state transition. Paths that run out of budget are immediately stopped and marked as pruned paths. Candidate state transitions that exceed the budget but meet the mandatory triggering conditions are marked as mandatory constraint transitions. The state update obtained from the deduction is mapped to the risk state mapping space hourly, the coordinates are aligned according to the risk anchor grid and the anchor point reprojection is performed, and the normalized coordinates at each time point are connected in time order to form the predicted risk state trajectory. The predicted risk state trajectory is compared with the risk elastic field hourly to mark the overload location and overload period. The overload duration and overload magnitude are summarized to generate the predicted risk state. Based on the predicted risk state, IoT security early warning information is generated and the early warning level is determined. 8.The IoT security early warning linkage decision method of claim 1, wherein, The step of evaluating candidate security linkage action sequences using a cross-domain dual graph neural network, determining the target security linkage action sequence, and executing it includes: Obtain the warning level and the current risk status description information of the corresponding IoT assets, extract the reverse recovery relationship associated with the assets from the reversible causal graph, form a reverse recovery subgraph, and obtain a set of executable safety linkage actions based on the device online status, interface availability and execution window. Based on the warning level, the linkage depth and execution time limit are set. Based on the reverse recovery relationship, the set of safety linkage actions is combined in a restricted manner to generate a candidate safety linkage action sequence that satisfies the action dependency relationship and does not violate the action conflict relationship. Using the current risk state description information as the initial state, each candidate safety linkage action sequence is reverse-engineered in the reverse recovery subgraph according to the action order, and the risk state change process obtained by the deduction is mapped to the risk state mapping space to form the corresponding candidate recovery trajectory. A cross-domain dual graph neural network is constructed to evaluate candidate security linkage action sequences. The cross-domain dual graph neural network consists of three sequentially connected layers, wherein: The risk propagation perception layer receives information on predicted risk state trajectories and positive causal relationships, and generates risk propagation representations. The action recovery modeling layer receives candidate safety linkage action sequences and recovery propagation paths in the reverse recovery subgraph, and generates action recovery representations. The third layer is the cross-domain dual fusion layer, which aligns and fuses the risk propagation representation and the action recovery representation. During the fusion process, recovery priority constraints and business impact constraints are introduced, and the risk reduction effect, recovery efficiency, business impact degree, execution cost and execution success probability corresponding to each candidate security linkage action sequence are output. Based on the evaluation results, the candidate safety linkage action sequences are sorted, and the safety linkage action sequence with the best overall effect is selected as the target safety linkage action sequence and executed. Safety data after linkage execution is collected, and the risk elasticity field, risk state mapping space and reversible causal graph are updated based on the safety data.