Risk disposal method, device and equipment for Internet of Things equipment, and medium
By extracting features and analyzing risk assessment models from the operational data of IoT devices, precise risk management strategies are generated, solving the problem of insufficient accuracy in risk management processes in existing technologies and achieving accurate assessment and effective management of device risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- YANGJIANG POWER SUPPLY BUREAU OF GUANGDONG POWER GRID
- Filing Date
- 2025-12-15
- Publication Date
- 2026-04-21
Smart Images

Figure CN121907503A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of the Internet of Things (IoT), and more particularly to methods, apparatuses, devices, and media for risk management of IoT devices. Background Technology
[0002] With the rapid development and widespread application of IoT technology, the scale of terminal devices connected to the IoT is growing exponentially, and their types are becoming increasingly complex and diverse, covering highly heterogeneous hardware such as industrial sensors and smart home devices. These devices continuously generate and upload massive amounts of operational data, which often includes personal privacy, sensitive corporate information, and even critical data related to public safety. Therefore, real-time and effective data risk management of IoT devices is not only an inherent requirement for preventing security threats such as data leakage and misuse, but also an inevitable choice to meet legal and regulatory compliance requirements and avoid regulatory risks.
[0003] Existing IoT device risk management technologies commonly employ a "one-size-fits-all" approach based on predefined static rules, such as fixed firewall rules. However, this method has significant drawbacks: its rules cannot be adapted to the real-time operating status of the devices, and it lacks the ability to accurately assess risks. Consequently, it is difficult to accurately evaluate the operational risks of IoT devices, thus failing to provide a scientific and effective basis for risk management decisions, ultimately resulting in insufficient accuracy in the risk management process. Summary of the Invention
[0004] This invention provides a method, apparatus, device, and medium for risk management of Internet of Things (IoT) devices, which can improve the accuracy of risk management processes by accurately assessing the operational risks of IoT devices.
[0005] In a first aspect, an embodiment of the present invention provides a risk management method for Internet of Things (IoT) devices, comprising:
[0006] Acquire operational data from IoT devices;
[0007] Feature extraction is performed on the operational data to obtain an operational feature vector. The operational feature vector is then input into a preset compliance risk assessment model to obtain a compliance risk prediction matrix for the operational data. Preset weights are used to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain a compliance risk index for the operational data. The compliance risk prediction matrix contains the assessment value of each risk element.
[0008] If the compliance risk index is greater than the preset risk threshold, the compliance risk index and the preset strategy database are matched for similarity to obtain a risk strategy template that meets the preset matching conditions. Based on the risk strategy template and the operation data, a risk disposal strategy is obtained.
[0009] The IoT device is subject to risk management based on the aforementioned risk management strategy.
[0010] By acquiring operational data from IoT devices, a comprehensive and authentic source of fundamental data is provided, laying the data foundation for accurate assessment and handling. Extracting operational feature vectors from this data allows for the screening and refinement of key characteristics strongly correlated with IoT device compliance risks, improving the targeting of risk assessments and the accuracy of handling processes. Inputting these feature vectors into a compliance risk assessment model yields a compliance risk prediction matrix, enabling a comprehensive and detailed breakdown and assessment of risks across different dimensions of the device, further enhancing the accuracy of risk assessment and handling. Weighting the compliance risk prediction matrix yields a compliance risk index, achieving a quantitative classification of device operational risks and providing a basis for subsequent risk handling strategies. The matching provides a precise risk quantification benchmark; when the compliance risk index exceeds the threshold, it matches with a preset strategy database to obtain a risk strategy template, avoiding the subjectivity and lag of manual strategy matching, ensuring the initial matching accuracy of risk disposal strategies, and improving the rationality and accuracy of the disposal process; generating risk disposal strategies based on risk strategy templates and operational data ensures that the risk disposal strategies not only comply with the disposal specifications of the corresponding risk level, but also fit the actual operating status of the equipment and the risk triggers, further improving the accuracy of the disposal process; handling risks of IoT devices based on risk disposal strategies ensures the precise execution of disposal actions and the effective mitigation of risks, ultimately improving the accuracy of the risk disposal process. This application can improve the accuracy of the risk disposal process by accurately assessing the operational risks of IoT devices.
[0011] Furthermore, the step of inputting the operational feature vector into a preset compliance risk assessment model to obtain the compliance risk prediction matrix of the operational data specifically includes:
[0012] The running feature vector is input into the spatiotemporal embedding layer to obtain the spatiotemporal encoding vector, wherein the compliance risk assessment model includes a spatiotemporal embedding layer, a hybrid convolutional module and a risk prediction layer;
[0013] The spatiotemporal encoding vector is input into the hybrid convolution module to obtain spatiotemporal convolution features;
[0014] The spatiotemporal convolutional features are input into the risk prediction layer, and the compliance risk prediction matrix is output.
[0015] This approach first transforms the operational feature vector into a spatiotemporal encoded vector, effectively encoding the spatiotemporal dimension information in the equipment operation data. Then, a hybrid convolution module extracts spatiotemporal convolutional features. Finally, the risk prediction layer outputs a compliance risk prediction matrix, enabling deeper mining and analysis of equipment risks from a spatiotemporal perspective. This significantly improves the comprehensiveness and accuracy of the risk prediction matrix, further ensuring the foundation for accurate risk assessment and helping to improve the accuracy of risk handling processes.
[0016] Furthermore, the step of inputting the spatiotemporal encoding vector into the hybrid convolution module to obtain spatiotemporal convolutional features specifically includes:
[0017] The spatiotemporal encoded vector is subjected to temporal feature convolution processing to obtain the first vector;
[0018] The spatiotemporal encoded vector is subjected to spatial correlation convolution to obtain a second vector;
[0019] The first vector and the second vector are fused to obtain the spatiotemporal convolutional features.
[0020] By performing convolution processing on the spatiotemporal encoded vectors in both temporal and spatial dimensions, we can capture the long-term and short-term dependencies of equipment operation risks on the time axis and the topological relationships between devices in the spatial dimension. Then, by fusing the two types of vectors, we can obtain spatiotemporal convolution features, which enables the accurate extraction of spatiotemporal coupling features of equipment risks. This makes the risk assessment more complete and the features more accurate, thereby enhancing the accuracy of the risk management process.
[0021] Furthermore, the step of using preset weights to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain the compliance risk index of the operational data specifically includes:
[0022] The first risk matrix is obtained by weighting each risk element in the compliance risk prediction matrix according to the preset risk type weights.
[0023] Based on the preset time decay factor and the first risk matrix, a second risk matrix is obtained;
[0024] The second risk matrix is adjusted regionally using a preset regional correction coefficient to obtain the third risk matrix;
[0025] The compliance risk index is obtained by aggregating the evaluation values of each risk element in the third risk matrix.
[0026] This approach distinguishes the importance of different risks based on risk type weights, highlighting the impact of core risks; it then uses a time decay factor to mitigate the interference of historical risks with lower timeliness; and finally, it combines regional correction coefficients to adapt to the differences in compliance requirements in different regions. This achieves a refined calibration of risk assessment values, making the final generated compliance risk index more closely match the priority and specificity of actual risk scenarios, and further improving the accuracy of risk handling processes.
[0027] Furthermore, the step of performing similarity matching between the compliance risk index and the preset strategy database to obtain a risk strategy template that meets the preset matching conditions specifically includes:
[0028] The compliance risk index is compared with the benchmark risk index range of each template in the preset strategy database to obtain several candidate strategy templates;
[0029] The similarity between the running feature vector and the baseline feature vector of each candidate strategy template is calculated to obtain several risk similarities;
[0030] The candidate strategy template with the highest risk similarity is used as the risk strategy template.
[0031] This approach first uses a rapid interval comparison based on the compliance risk index to screen candidate templates, and then uses a refined similarity calculation based on the operational feature vector to determine the final template. This ensures that the selected risk strategy template can not only match the current risk level, but also adapt to the specific operating status of the equipment, thereby improving the accuracy of risk strategy matching and ensuring the accuracy of the risk handling process.
[0032] Furthermore, the risk management strategy derived based on the risk strategy template and the operational data specifically includes:
[0033] The risk strategy template is parsed to determine the sequence of actions to be taken and the parameter configuration rules.
[0034] Based on the parameter configuration rules, the parameters in the action sequence are filled in using the operational data to generate the risk management strategy.
[0035] By first analyzing the standardized handling actions and parameter rules of the strategy template, and then filling in specific parameters with real-time equipment operating data, the transformation from a general strategy template to a customized handling strategy is achieved. This allows the risk handling strategy to not only follow the handling specifications of the corresponding risk level, but also accurately adapt to the actual operating conditions of the equipment and the risk triggers, further improving the accuracy of the risk handling process.
[0036] Furthermore, after performing risk mitigation on the IoT device based on the risk mitigation strategy, the method further includes:
[0037] Acquire execution data generated during the risk management process, wherein the execution data includes execution actions, execution objects, and execution start and end times;
[0038] Based on the execution data and the blockchain's layered consensus mechanism, risk disposal credentials are obtained;
[0039] The risk disposal certificate is processed on the blockchain to obtain the risk disposal certificate chain.
[0040] By using a blockchain-based layered consensus mechanism to generate an immutable credential chain from the risk management execution data, the entire risk management process can be documented and traced, making the process traceable and verifiable, and indirectly improving the accuracy of the overall risk management process.
[0041] Secondly, an embodiment of the present invention provides a risk management device for Internet of Things (IoT) devices, comprising a first module, a second module, a third module, and a fourth module;
[0042] The first module is used to acquire the operating data of IoT devices;
[0043] The second module is used to extract features from the operating data to obtain an operating feature vector, input the operating feature vector into a preset compliance risk assessment model to obtain a compliance risk prediction matrix of the operating data, and use preset weights to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain a compliance risk index of the operating data, wherein the compliance risk prediction matrix contains the assessment value of each risk element;
[0044] The third module is used to perform similarity matching between the compliance risk index and the preset strategy database if the compliance risk index is greater than the preset risk threshold, to obtain a risk strategy template that meets the preset matching conditions, and to obtain a risk disposal strategy based on the risk strategy template and the operation data.
[0045] The fourth module is used to handle risks of the IoT device based on the risk management strategy.
[0046] This approach, by acquiring operational data from IoT devices through the first module, provides a comprehensive and authentic source of foundational data, laying the data foundation for accurate assessment and handling. The second module extracts operational feature vectors from the operational data, allowing for the screening and refinement of key features strongly correlated with IoT device compliance risks, improving the targeting of risk assessments and the accuracy of handling processes. Inputting these operational feature vectors into a compliance risk assessment model yields a compliance risk prediction matrix, enabling a comprehensive and detailed breakdown and assessment of risks across different dimensions of the device, further enhancing the accuracy of risk assessment and handling. Weighting the compliance risk prediction matrix yields a compliance risk index, achieving a quantitative classification of device operational risks and providing a basis for subsequent risk handling strategies. The first module provides a precise risk quantification benchmark; the second module matches the risk strategy template with the preset strategy database when the compliance risk index exceeds the threshold, avoiding the subjectivity and lag of manual strategy matching, ensuring the initial matching accuracy of risk disposal strategies, and improving the rationality and accuracy of the disposal process; the third module generates risk disposal strategies based on risk strategy templates and operational data, ensuring that the risk disposal strategies not only comply with the disposal specifications of the corresponding risk level, but also fit the actual operating status of the equipment and the risk triggers, further improving the accuracy of the disposal process; the fourth module performs risk disposal on IoT devices based on risk disposal strategies, ensuring the precise execution of disposal actions and the effective mitigation of risks, ultimately improving the accuracy of the risk disposal process.
[0047] Thirdly, another embodiment of the present invention also provides a terminal device, including: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus;
[0048] The memory is used to store at least one executable instruction that causes the processor to perform an operation of a risk management method for an Internet of Things (IoT) device.
[0049] Fourthly, another embodiment of the present invention provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device or apparatus containing the computer-readable storage medium to perform a risk management method for an Internet of Things (IoT) device. Attached Figure Description
[0050] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0051] Figure 1This is a flowchart illustrating one embodiment of the risk management method for IoT devices provided in this application;
[0052] Figure 2 This is a flowchart illustrating steps S201 to S203 provided in this application;
[0053] Figure 3 This is a schematic diagram of the risk management device for the Internet of Things (IoT) device provided in this application. Detailed Implementation
[0054] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.
[0056] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.
[0057] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0058] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0059] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).
[0060] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.
[0061] In the field of the Internet of Things (IoT), real-time and effective data risk management of devices is crucial for preventing data security threats and meeting compliance requirements. However, this field currently faces significant technological bottlenecks. The existing technology's "one-size-fits-all" management approach using predefined static rules has significant flaws: these rules cannot be dynamically adapted to the real-time operating status of devices, and they lack the ability to accurately assess risks. This makes it difficult to accurately evaluate the operational risks of devices, and fails to provide a scientific basis for risk management decisions, ultimately resulting in insufficient accuracy in the risk management process.
[0062] See Figure 1 In order to improve the accuracy of the risk disposal process by accurately assessing the operational risks of IoT devices, an embodiment of the present invention provides a risk disposal method for IoT devices, including steps S101 to S104.
[0063] Step S101: Obtain the operating data of the IoT device;
[0064] In some embodiments, acquiring operational data of IoT devices specifically includes: concurrently acquiring raw operational data from multiple heterogeneous IoT devices connected to the platform through multiple data acquisition agents deployed on the IoT platform side, with a predetermined sampling period or event triggering mechanism.
[0065] It should be noted that the operational data includes, but is not limited to, the device's own status parameters (such as CPU utilization, memory usage, and number of network connections), the business data content generated by the device (such as sensor readings, control commands, and user identifiers), and environmental information during data transmission (such as source / destination IP addresses, communication protocols, transmission delays, and signal strength). The data acquisition agent follows a unified data access protocol (such as MQTT and CoAP) and supports format parsing and preliminary encapsulation of device data from different manufacturers and with different communication standards to form a structured operational data stream.
[0066] Step S102: Extract features from the running data to obtain a running feature vector. Input the running feature vector into a preset compliance risk assessment model to obtain a compliance risk prediction matrix for the running data. Then, use preset weights to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain a compliance risk index for the running data. The compliance risk prediction matrix contains the assessment value of each risk element.
[0067] In some embodiments, feature extraction is performed on the operational data to obtain an operational feature vector. Specifically, this includes: calculating the time-series statistical features of key indicators (such as CPU utilization, memory usage, and network connection count) for device status parameters in the operational data using a sliding time window (e.g., 5 minutes), including the mean, standard deviation, maximum value, and the mean difference between adjacent windows, to construct a state time-series feature vector reflecting the dynamic changes in device load; performing real-time scanning of business data content using a predefined sensitive information identification rule base and data format compliance template (e.g., using regular expressions to match PII fields and verify data boundaries), and quantifying the matching results into a content compliance feature vector; extracting network behavior features (e.g., connection frequency per unit time, proportion of non-standard communication ports, and average transmission delay) and time-stamp-based periodic communication behavior features (e.g., hourly communication density changes) for transmission environment information to form a network and spatiotemporal feature vector; and finally standardizing the state time-series feature vector, content compliance feature vector, and network and spatiotemporal feature vector, and integrating and unifying the dimensions using vector concatenation to output the operational feature vector.
[0068] Please refer to Figure 2 In some embodiments, the step of inputting the running feature vector into a preset compliance risk assessment model to obtain the compliance risk prediction matrix of the running data includes steps S201 to S203.
[0069] Step S201: Input the running feature vector into the spatiotemporal embedding layer to obtain the spatiotemporal encoding vector, wherein the compliance risk assessment model includes a spatiotemporal embedding layer, a hybrid convolutional module and a risk prediction layer;
[0070] In some embodiments, the running feature vector is input into the spatiotemporal embedding layer to obtain a spatiotemporal encoded vector. Specifically, the compliance risk assessment model includes a spatiotemporal embedding layer, a hybrid convolutional module, and a risk prediction layer. First, spatiotemporal related information such as the device's unique identifier and the device's BeiDou geographical location is extracted from the running feature vector. Then, through the encoding logic built into the spatiotemporal embedding layer, the device ID is converted into a high-dimensional discrete vector to represent the device's identity features. At the same time, the BeiDou coordinates are converted into an H3 geographic grid index and mapped to a spatial feature vector of the same dimension. Subsequently, the identity features, spatial features, and other features such as device status, data content, and transmission environment in the running feature vector are fused together to finally generate a high-dimensional spatiotemporal encoded vector containing the device's identity, spatial location, and running status.
[0071] Step S202: Input the spatiotemporal encoding vector into the hybrid convolution module to obtain spatiotemporal convolution features;
[0072] In some embodiments, inputting the spatiotemporal encoding vector into the hybrid convolution module to obtain spatiotemporal convolutional features specifically includes: performing temporal feature convolution processing on the spatiotemporal encoding vector to obtain a first vector; performing spatial correlation convolution processing on the spatiotemporal encoding vector to obtain a second vector; and fusing the first vector and the second vector to obtain spatiotemporal convolutional features.
[0073] Specifically, the temporal feature convolution processing employs bi-directional dilated causal convolution to convolve the spatiotemporal encoded vector along the time axis to capture the long-term and short-term dependencies of device operation data in the time dimension, outputting the first vector. The spatial correlation convolution processing uses a dynamic graph convolutional network to construct a dynamic topology graph based on the communication or geographical proximity relationships between devices, and performs convolution operations on the graph to model the spatial correlations between devices, outputting the second vector. Finally, the features of the first and second vectors are fused by element-wise weighted summation to obtain the spatiotemporal convolutional features.
[0074] By performing convolution processing on the spatiotemporal encoded vectors in both temporal and spatial dimensions, we can capture the long-term and short-term dependencies of equipment operation risks on the time axis and the topological relationships between devices in the spatial dimension. Then, by fusing the two types of vectors, we can obtain spatiotemporal convolution features, which enables the accurate extraction of spatiotemporal coupling features of equipment risks. This makes the risk assessment more complete and the features more accurate, thereby enhancing the accuracy of the risk management process.
[0075] Step S203: Input the spatiotemporal convolutional features into the risk prediction layer and output the compliance risk prediction matrix;
[0076] In some embodiments, the spatiotemporal convolutional features are input into the risk prediction layer to output the compliance risk prediction matrix. Specifically, this includes: inputting the spatiotemporal convolutional features into the multilayer perceptron (MLP) network of the risk prediction layer; first, performing nonlinear mapping and dimensionality reduction on the spatiotemporal convolutional features through multiple fully connected layers to extract key feature vectors affecting compliance risk; then, outputting the risk probabilities of different dimensions based on an activation function (such as softmax); and simultaneously, filling the corresponding matrix positions with the risk assessment values of each dimension according to the four dimensions of device, data classification, risk type, and time slice, so that each element in the matrix corresponds to the assessment value of a specific risk type of a certain device under a specific time slice, and finally generating the compliance risk prediction matrix.
[0077] It should be noted that the training process of the compliance risk assessment model is as follows: First, based on historical system operation data and the compliance audit results manually determined during the corresponding period, a structured training sample set is constructed. Each sample is input by a historical operation feature vector and a real risk label matrix organized according to four dimensions: device, data type, risk category, and time slice, as a supervision signal. Second, the parameters of the spatiotemporal embedding layer, the hybrid convolutional module, and the risk prediction layer are initialized, and the loss function is defined. Next, a batch of historical feature vectors are input into the model through forward propagation. They are sequentially processed by the spatiotemporal embedding layer to generate encoded vectors. The hybrid convolutional module uses bidirectional dilated causal convolution to extract temporal dependency features and captures spatial correlation features between devices based on dynamic graph convolutional networks. The two types of features are then fused and input into the multilayer perceptron of the risk prediction layer to output a risk prediction matrix. Then, the loss between the prediction matrix and the historical real label matrix is calculated. The model parameters are iteratively optimized through backpropagation and gradient descent algorithms so that the model output gradually approximates the historical real risk distribution. During the training process, the model performance is monitored and hyperparameters are adjusted using a validation set. Finally, the model training is completed after the model meets the evaluation criteria on an independent test set, and the parameters are solidified for compliance risk prediction of real-time operating data.
[0078] This approach first transforms the operational feature vector into a spatiotemporal encoded vector, effectively encoding the spatiotemporal dimension information in the equipment operation data. Then, a hybrid convolution module extracts spatiotemporal convolutional features. Finally, the risk prediction layer outputs a compliance risk prediction matrix, enabling deeper mining and analysis of equipment risks from a spatiotemporal perspective. This significantly improves the comprehensiveness and accuracy of the risk prediction matrix, further ensuring the foundation for accurate risk assessment and helping to improve the accuracy of risk handling processes.
[0079] In some embodiments, the step of using preset weights to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain the compliance risk index of the operating data specifically includes: performing weighted calculations on each risk element in the compliance risk prediction matrix according to preset risk type weights to obtain a first risk matrix; obtaining a second risk matrix based on a preset time decay factor and the first risk matrix; performing regional adjustments on the second risk matrix using a preset regional correction coefficient to obtain a third risk matrix; and aggregating the evaluation values of each risk element in the third risk matrix to obtain the compliance risk index. Specifically, different weights are assigned based on the importance of different risk types (e.g., a weight of 0.3 is assigned to the risk of non-compliance with communication protocols, and a weight of 0.1 is assigned to the risk of routine equipment operation). Then, the elements in the compliance risk prediction matrix are weighted according to the preset risk type weights to obtain the first risk matrix. Next, a time decay factor is set based on the exponential decay model, and the risk values of different time slices in the first risk matrix are attenuated using the time decay factor (e.g., a decay coefficient of 0.3 is set for historical risk values 24 hours ago) to generate the second risk matrix. Then, a regional correction coefficient is set according to the differences in compliance regulatory requirements of the region where the equipment is located (e.g., a correction coefficient of 1.2 is set for the region where cross-border data transmission equipment is located, and a correction coefficient of 1.0 is set for equipment in ordinary domestic regions). The second risk matrix is then calibrated regionally using the regional correction coefficient to obtain the third risk matrix. Finally, the evaluation values of all elements in the third risk matrix are aggregated to obtain the final compliance risk index.
[0080] It should be noted that, due to the time-sensitive nature of risks, some risk events may gradually become irrelevant over time. Therefore, a time decay factor is introduced to attenuate risks. Since different regions may have different levels of compliance risk, for example, some countries or regions have stricter regulations, a regional correction coefficient can be set to adjust the risk based on the region where the equipment is located. The time decay factor can also be set through a linear decay model.
[0081] This approach distinguishes the importance of different risks based on risk type weights, highlighting the impact of core risks; it then uses a time decay factor to mitigate the interference of historical risks with lower timeliness; and finally, it combines regional correction coefficients to adapt to the differences in compliance requirements in different regions. This achieves a refined calibration of risk assessment values, making the final generated compliance risk index more closely match the priority and specificity of actual risk scenarios, and further improving the accuracy of risk handling processes.
[0082] Step S103: If the compliance risk index is greater than the preset risk threshold, the compliance risk index and the preset strategy database are matched for similarity to obtain a risk strategy template that meets the preset matching conditions. Based on the risk strategy template and the operation data, a risk disposal strategy is obtained.
[0083] In some embodiments, if the compliance risk index is greater than a preset risk threshold, specifically, a preset risk threshold (e.g., set to 0.5) is first set. When the calculated compliance risk index is greater than the threshold, the device is determined to be in a high-risk state. If the threshold is not exceeded, it is indicated to be in a low-risk state, and no risk control is required.
[0084] It should be noted that this risk threshold can be dynamically adjusted based on the frequency of historical compliance events, industry compliance standards, or user-defined strategies.
[0085] In some embodiments, the step of performing similarity matching between the compliance risk index and the preset strategy database to obtain a risk strategy template that meets preset matching conditions specifically includes: comparing the compliance risk index with the baseline risk index range of each template in the preset strategy database to obtain several candidate strategy templates; calculating the similarity between the operating feature vector and the baseline feature vector of each candidate strategy template to obtain several risk similarities; and using the candidate strategy template with the highest risk similarity as the final risk strategy template. Specifically, firstly, all pre-stored risk handling templates in the preset strategy database are traversed, and templates whose baseline risk index range can cover the current device compliance risk index are selected to form a candidate strategy template pool; the cosine similarity algorithm is used to calculate the matching degree between the device operating feature vector and the baseline feature vector of each candidate template to obtain several risk similarities; finally, the candidate template with the highest similarity value is selected as the final risk strategy template.
[0086] For example, the process of constructing a pre-defined strategy database includes: collecting historical compliance risk handling cases; extracting equipment operation characteristics, risk indices, and effective handling actions from the cases; forming standard handling templates for different risk levels and scenarios through cluster analysis; each template is associated with a benchmark risk index range and a benchmark feature vector, and multiple templates constitute the pre-defined strategy database.
[0087] This approach first uses a rapid interval comparison based on the compliance risk index to screen candidate templates, and then uses a refined similarity calculation based on the operational feature vector to determine the final template. This ensures that the selected risk strategy template can not only match the current risk level, but also adapt to the specific operating status of the equipment, thereby improving the accuracy of risk strategy matching and ensuring the accuracy of the risk handling process.
[0088] In some embodiments, obtaining a risk handling strategy based on the risk strategy template and the operational data specifically includes: parsing the risk strategy template to determine the sequence of handling actions and parameter configuration rules; and using the operational data to fill in the parameters in the sequence of handling actions in conjunction with the parameter configuration rules to generate the risk handling strategy. Specifically, the selected risk strategy template is first parsed to extract the preset standardized sequence of handling actions (such as data encryption, access control, and abnormal behavior reporting) and the corresponding parameter configuration rules (such as encryption protocol type selection rules, access whitelist range definition rules, and reporting node address allocation rules); then, real-time operational data of the device is retrieved, and parameters such as the device IP address, current communication protocol version, and data transmission port are extracted. The blank parameters in the sequence of handling actions are then filled in according to the parameter configuration rules to finally generate a risk handling strategy adapted to the actual operating state of the device.
[0089] By first analyzing the standardized handling actions and parameter rules of the strategy template, and then filling in specific parameters with real-time equipment operating data, the transformation from a general strategy template to a customized handling strategy is achieved. This allows the risk handling strategy to not only follow the handling specifications of the corresponding risk level, but also accurately adapt to the actual operating conditions of the equipment and the risk triggers, further improving the accuracy of the risk handling process.
[0090] Step S104: Perform risk management on the IoT device based on the risk management strategy;
[0091] In some embodiments, risk mitigation of the IoT device based on the risk mitigation strategy includes: parsing the risk mitigation strategy into specific control instructions through the control interface of the IoT platform and sending them to the target device or network control node; dynamically executing the mitigation actions according to the strategy content, such as automatically configuring firewall rules to isolate network access of high-risk devices, sending instructions to the device to suspend non-critical data reporting functions, or triggering the device's local security agent and initiating encrypted transmission and password update processes; during execution, the system synchronously monitors the real-time operating data feedback of the device to verify whether the risk indicators have effectively decreased; if the risk does not meet expectations after mitigation, the strategy upgrade mechanism is automatically triggered to match and execute higher-intensity mitigation actions according to preset rules, thereby achieving risk mitigation of the IoT device.
[0092] In some embodiments, after performing risk management on the IoT device based on the risk management strategy, the method further includes: acquiring execution data generated during the risk management process, wherein the execution data includes execution actions, execution objects, and execution start and end times; obtaining risk management credentials based on the execution data and the layered consensus mechanism of the blockchain; and processing the risk management credentials on the blockchain to obtain a risk management credential chain. Specifically, the process begins by collecting execution data from the entire risk management process, including specific actions, targets, and start and end times. Then, it integrates with the BeiDou atomic clock timing service to embed traceable spatiotemporal stamps into the execution data and converts the device's BeiDou coordinates into an H3 geographic grid index. Combining the original execution data with device classification information, a unique data fingerprint is synthesized through a multi-level hash tree structure (first-level nodes store the original data and classification tags, second-level nodes aggregate the hashes of lower-level data), thus completing the secure encapsulation of the execution data. Next, based on a blockchain layered consensus mechanism, lower-level consensus nodes perform hash verification and cross-node block synchronization on the encapsulated data, while higher-level consensus nodes verify the compliance and effectiveness of the management actions. Upon successful verification, a risk management certificate containing the spatiotemporal stamp, data fingerprint, and complete execution record is generated. Finally, the certificates for each management event are linked in chronological order, with each newly generated block associated with the hash value of the previous block, forming an immutable risk management certificate chain.
[0093] By using a blockchain-based layered consensus mechanism to generate an immutable credential chain from the risk management execution data, the entire risk management process can be documented and traced, making the process traceable and verifiable, and indirectly improving the accuracy of the overall risk management process.
[0094] By acquiring operational data from IoT devices, a comprehensive and authentic source of fundamental data is provided, laying the data foundation for accurate assessment and handling. Extracting operational feature vectors from this data allows for the screening and refinement of key characteristics strongly correlated with IoT device compliance risks, improving the targeting of risk assessments and the accuracy of handling processes. Inputting these feature vectors into a compliance risk assessment model yields a compliance risk prediction matrix, enabling a comprehensive and detailed breakdown and assessment of risks across different dimensions of the device, further enhancing the accuracy of risk assessment and handling. Weighting the compliance risk prediction matrix yields a compliance risk index, achieving a quantitative classification of device operational risks and providing a basis for subsequent risk handling strategies. The matching provides a precise risk quantification benchmark; when the compliance risk index exceeds the threshold, it matches with a preset strategy database to obtain a risk strategy template, avoiding the subjectivity and lag of manual strategy matching, ensuring the initial matching accuracy of risk disposal strategies, and improving the rationality and accuracy of the disposal process; generating risk disposal strategies based on risk strategy templates and operational data ensures that the risk disposal strategies not only comply with the disposal specifications of the corresponding risk level, but also fit the actual operating status of the equipment and the risk triggers, further improving the accuracy of the disposal process; handling risks of IoT devices based on risk disposal strategies ensures the precise execution of disposal actions and the effective mitigation of risks, ultimately improving the accuracy of the risk disposal process. This application can improve the accuracy of the risk disposal process by accurately assessing the operational risks of IoT devices.
[0095] See Figure 3 Based on the above method embodiments, corresponding device embodiments are provided;
[0096] An embodiment of the present invention provides a risk management device for Internet of Things (IoT) devices, including a first module 100, a second module 200, a third module 300 and a fourth module 400;
[0097] The first module 100 is used to acquire the operating data of IoT devices;
[0098] The second module 200 is used to extract features from the operating data to obtain an operating feature vector, input the operating feature vector into a preset compliance risk assessment model to obtain a compliance risk prediction matrix of the operating data, and use preset weights to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain a compliance risk index of the operating data, wherein the compliance risk prediction matrix contains the assessment value of each risk element;
[0099] The third module 300 is used to perform similarity matching between the compliance risk index and the preset strategy database if the compliance risk index is greater than the preset risk threshold, to obtain a risk strategy template that meets the preset matching conditions, and to obtain a risk disposal strategy based on the risk strategy template and the operation data.
[0100] The fourth module 400 is used to perform risk management on the IoT device based on the risk management strategy.
[0101] This approach, by acquiring operational data from IoT devices through the first module, provides a comprehensive and authentic source of foundational data, laying the data foundation for accurate assessment and handling. The second module extracts operational feature vectors from the operational data, allowing for the screening and refinement of key features strongly correlated with IoT device compliance risks, improving the targeting of risk assessments and the accuracy of handling processes. Inputting these operational feature vectors into a compliance risk assessment model yields a compliance risk prediction matrix, enabling a comprehensive and detailed breakdown and assessment of risks across different dimensions of the device, further enhancing the accuracy of risk assessment and handling. Weighting the compliance risk prediction matrix yields a compliance risk index, achieving a quantitative classification of device operational risks and providing a basis for subsequent risk handling strategies. The first module provides a precise risk quantification benchmark; the second module matches the risk strategy template with the preset strategy database when the compliance risk index exceeds the threshold, avoiding the subjectivity and lag of manual strategy matching, ensuring the initial matching accuracy of risk disposal strategies, and improving the rationality and accuracy of the disposal process; the third module generates risk disposal strategies based on risk strategy templates and operational data, ensuring that the risk disposal strategies not only comply with the disposal specifications of the corresponding risk level, but also fit the actual operating status of the equipment and the risk triggers, further improving the accuracy of the disposal process; the fourth module performs risk disposal on IoT devices based on risk disposal strategies, ensuring the precise execution of disposal actions and the effective mitigation of risks, ultimately improving the accuracy of the risk disposal process.
[0102] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention, and can implement the risk management method for IoT devices provided by any of the above-described method embodiments of the present invention.
[0103] It should be noted that the device embodiments described above are merely illustrative, and some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can specifically be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0104] Based on the above-described embodiments of the risk management method for IoT devices, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the risk management method for IoT devices according to any embodiment of the present invention.
[0105] For example, in this embodiment, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the terminal device.
[0106] The terminal device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.
[0107] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.
[0108] Based on the above-described method embodiments, another embodiment of the present invention provides a computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the risk management method for IoT devices described in any of the above-described method embodiments of the present invention.
[0109] The modules / units integrated in the device / terminal equipment, if implemented as software functional units and sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0110] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A risk management method for Internet of Things (IoT) devices, characterized in that, include: Acquire operational data from IoT devices; Feature extraction is performed on the operational data to obtain an operational feature vector. The operational feature vector is then input into a preset compliance risk assessment model to obtain a compliance risk prediction matrix for the operational data. Preset weights are used to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain a compliance risk index for the operational data. The compliance risk prediction matrix contains the assessment value of each risk element. If the compliance risk index is greater than the preset risk threshold, the compliance risk index and the preset strategy database are matched for similarity to obtain a risk strategy template that meets the preset matching conditions. Based on the risk strategy template and the operation data, a risk disposal strategy is obtained. The IoT device is subject to risk management based on the aforementioned risk management strategy.
2. The risk management method for IoT devices as described in claim 1, characterized in that, The step of inputting the operational feature vector into a preset compliance risk assessment model to obtain the compliance risk prediction matrix of the operational data specifically includes: The running feature vector is input into the spatiotemporal embedding layer to obtain the spatiotemporal encoding vector, wherein the compliance risk assessment model includes a spatiotemporal embedding layer, a hybrid convolutional module and a risk prediction layer; The spatiotemporal encoding vector is input into the hybrid convolution module to obtain spatiotemporal convolution features; The spatiotemporal convolutional features are input into the risk prediction layer, and the compliance risk prediction matrix is output.
3. The risk management method for IoT devices as described in claim 2, characterized in that, The step of inputting the spatiotemporal encoding vector into the hybrid convolution module to obtain spatiotemporal convolutional features specifically includes: The spatiotemporal encoded vector is subjected to temporal feature convolution processing to obtain the first vector; The spatiotemporal encoded vector is subjected to spatial correlation convolution to obtain a second vector; The first vector and the second vector are fused to obtain the spatiotemporal convolutional features.
4. The risk management method for IoT devices as described in claim 1, characterized in that, The step of weighting each risk element in the compliance risk prediction matrix using preset weights to obtain the compliance risk index of the operational data specifically includes: The first risk matrix is obtained by weighting each risk element in the compliance risk prediction matrix according to the preset risk type weights. Based on the preset time decay factor and the first risk matrix, a second risk matrix is obtained; The second risk matrix is adjusted regionally using a preset regional correction coefficient to obtain the third risk matrix; The compliance risk index is obtained by aggregating the evaluation values of each risk element in the third risk matrix.
5. The risk management method for IoT devices as described in claim 1, characterized in that, The step of performing similarity matching between the compliance risk index and the preset strategy database to obtain a risk strategy template that meets the preset matching conditions specifically includes: The compliance risk index is compared with the benchmark risk index range of each template in the preset strategy database to obtain several candidate strategy templates; The similarity between the running feature vector and the baseline feature vector of each candidate strategy template is calculated to obtain several risk similarities; The candidate strategy template with the highest risk similarity is used as the risk strategy template.
6. The risk management method for IoT devices as described in claim 1, characterized in that, The risk management strategy derived based on the risk strategy template and the operational data specifically includes: The risk strategy template is parsed to determine the sequence of actions to be taken and the parameter configuration rules. Based on the parameter configuration rules, the parameters in the action sequence are filled in using the operational data to generate the risk management strategy.
7. The risk management method for IoT devices as described in any one of claims 1-6, characterized in that, After performing risk mitigation on the IoT device based on the risk mitigation strategy, the method further includes: Acquire execution data generated during the risk management process, wherein the execution data includes execution actions, execution objects, and execution start and end times; Based on the execution data and the blockchain's layered consensus mechanism, risk disposal credentials are obtained; The risk disposal certificate is processed on the blockchain to obtain the risk disposal certificate chain.
8. A risk management device for Internet of Things (IoT) devices, characterized in that, It includes Module 1, Module 2, Module 3, and Module 4; The first module is used to acquire the operating data of IoT devices; The second module is used to extract features from the operating data to obtain an operating feature vector, input the operating feature vector into a preset compliance risk assessment model to obtain a compliance risk prediction matrix of the operating data, and use preset weights to perform weighted calculations on each risk element in the compliance risk prediction matrix to obtain a compliance risk index of the operating data, wherein the compliance risk prediction matrix contains the assessment value of each risk element; The third module is used to perform similarity matching between the compliance risk index and the preset strategy database if the compliance risk index is greater than the preset risk threshold, to obtain a risk strategy template that meets the preset matching conditions, and to obtain a risk disposal strategy based on the risk strategy template and the operation data. The fourth module is used to handle risks of the IoT device based on the risk management strategy.
9. A terminal device, characterized in that, include: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable instruction that causes the processor to perform the operation of a risk management method for an Internet of Things device as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device or apparatus containing the computer-readable storage medium to perform a risk management method for an Internet of Things device as described in any one of claims 1 to 7.