Network security level protection lightweight evaluation method suitable for Internet of Things scene

By combining a dynamic indicator library and a collaborative architecture topology, the weights and evaluation thresholds of indicators are dynamically adjusted to optimize terminal communication, thus solving the problem of network security level protection assessment for IoT devices and achieving efficient, accurate, lightweight assessment and communication optimization.

CN121967480APending Publication Date: 2026-05-01BEIJING GUOHUA CENTURY ELECTRONIC TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING GUOHUA CENTURY ELECTRONIC TECH CO LTD
Filing Date
2026-03-09
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing IoT network security level protection assessment technologies are ill-suited to the diversity and complexity of new energy IoT devices. They cannot dynamically adjust indicator weights and assessment thresholds, resulting in high resource consumption, insufficient real-time performance, inability to comprehensively monitor the connection relationship and data flow between terminals and platforms, and inability to provide accurate architectural support.

Method used

A dynamic indicator library is established, indicator association logic is generated, a collaborative architecture topology diagram is constructed, an improved BiLSTM model is used for lightweight evaluation, indicator weights and evaluation thresholds are dynamically adjusted, and terminal communication is optimized.

Benefits of technology

It enables efficient and accurate network security level protection assessment in resource-constrained environments, reduces resource consumption, improves real-time performance and communication security, and optimizes terminal communication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967480A_ABST
    Figure CN121967480A_ABST
Patent Text Reader

Abstract

The invention discloses a network security level protection lightweight evaluation method suitable for an Internet of Things scene, and belongs to the technical field of the Internet of Things, and the method comprises the steps: building a dynamic index library, obtaining, sorting and analyzing the common characteristics, demand differences, terminal types and resource constraint conditions of new energy Internet of Things equipment in different application scenes, and carrying out the analysis of the common characteristics, demand differences, terminal types and resource constraint conditions. Dividing index hierarchies according to basic insurance indexes, scene exclusive indexes and dynamic adaptation factors, generating an index screening principle, generating index association logic in combination with the index hierarchies and the index screening principle, establishing a collaborative architecture topological graph, monitoring the Internet of Things terminal in real time, and obtaining terminal resource data of the Internet of Things terminal. A cross-scene lightweight evaluation model is established, lightweight evaluation is performed on a collaborative architecture topological graph based on terminal resource data, and terminal communication is optimized, so that an evaluation result can meet actual security requirements of different scenes, and security risks of different scenes of the new energy Internet of Things are accurately identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of Internet of Things (IoT) technology, specifically, it relates to a lightweight assessment method for network security level protection applicable to IoT scenarios. Background Technology

[0002] With the advancement of dual-carbon goals, the new energy industry and Internet of Things (IoT) technology are deeply integrated, resulting in a surge in the number of new energy IoT devices such as charging piles, battery swapping cabinets, and smart energy storage cabinets. Their application scenarios cover multiple fields such as residential charging, commercial operation and maintenance, and industrial energy storage. The types of device terminals are diverse, the communication protocols are complex, and the terminals often have resource constraints such as limited computing power, power consumption sensitivity, and complex deployment environments. These IoT devices are typically characterized by large node scale, diverse deployment environments, and limited resources, and they face complex application scenarios and dynamically changing operating environments.

[0003] Existing IoT network security level protection assessment technologies have many shortcomings. They are difficult to meet the actual needs of new energy IoT scenarios, and it is difficult to extract specific indicators for the different needs of different application scenarios and terminal type characteristics of new energy IoT. Moreover, the indicator weights and evaluation thresholds are fixed and cannot be dynamically adjusted, resulting in poor scenario adaptability. In addition, most of them adopt the full indicator assessment mode, which results in excessive resource consumption and insufficient real-time performance in the assessment process. Furthermore, existing solutions do not comprehensively monitor the connection relationship and data flow between terminals and platforms, and have not established a collaborative mechanism for assessment results and terminal communication optimization, thus failing to provide accurate architectural support for the assessment. Summary of the Invention

[0004] To address the aforementioned problems and technical deficiencies, this application adopts the following technical solution: a lightweight assessment method for network security level protection applicable to IoT scenarios, including: Establish a dynamic indicator database to acquire, organize, and analyze the common characteristics, demand differences, terminal types, and resource constraints of new energy IoT devices in different application scenarios; The indicator hierarchy is divided according to basic security level protection indicators, scenario-specific indicators and dynamic adaptation factors. Indicator selection principles are generated based on common characteristics, demand differences and terminal types. Indicator association logic is generated by combining indicator hierarchy and indicator selection principles. Establish a collaborative architecture topology based on the connection relationship between IoT terminals and server platforms, monitor IoT terminals in real time, and obtain terminal resource data of IoT terminals. Establish a cross-scenario lightweight evaluation model, conduct lightweight evaluation of the collaborative architecture topology based on terminal resource data, and optimize terminal communication based on the lightweight evaluation results.

[0005] Preferably, the basic security protection indicators are generated based on Security Protection Standard 2.0, which is the Cybersecurity Security Protection Standard 2.0. Scenario-specific indicators are extracted for different application scenarios of the new energy Internet of Things. The dynamic adaptation factor is an adaptation factor for risk level, business period, and equipment resource status. It dynamically adjusts indicator weights and evaluation thresholds based on an indicator weight adjustment algorithm. The calculation formula for the dynamic adaptation factor is as follows: Wi' = Wi*(α*R+β*T+γ*S) Wherein, Wi' is the current dynamic adaptation factor, Wi is the previous dynamic adaptation factor, R is the risk factor, which is dynamically adjusted according to the frequency of each risk level in history, T is the time period factor, which is adjusted according to the business peak and trough periods, S is the resource status factor, which is adjusted according to the occupancy rate of each hardware in the IoT terminal, and α, β and γ are the normalization coefficients of each factor, which are configured according to the scenario.

[0006] Furthermore, the generation of the indicator association logic involves establishing a dependency and conflict relationship graph between indicators based on the terminal type and the current resource status factor S. Specific steps include: Calculate the information entropy of each indicator, determine the indicator discrimination, determine the initial weight of the indicator by combining the analytic hierarchy process, and dynamically adjust the screening threshold according to the current resource status factor. A minimum necessary evaluation set is selected from the dynamic indicator library based on the indicator discrimination, the initial weight of the indicator, and the screening threshold. The number of indicators in the evaluation set is less than or equal to the preset number threshold. By combining the minimum necessary evaluation set, an adjacency matrix is ​​used to represent the binary relationship graph of dependency and conflict between indicators.

[0007] Furthermore, the collaborative architecture topology diagram is created by using a cross-protocol adaptation interface to uniformly parse the communication protocols between IoT terminals and the platform, perform lightweight protocol conversion, and then draw a collaborative architecture topology diagram including terminal nodes, communication links, and data flow.

[0008] Furthermore, the lightweight evaluation involves modeling a terminal behavior baseline that matches each IoT terminal, including: The core behavioral characteristics of the data acquisition terminal during normal operation are used as baseline characteristics. An improved K-means clustering algorithm is used to cluster baseline features to generate a baseline range for normal behavior. The baseline of terminal behavior is evaluated based on dynamic indicators and evaluation thresholds; The baseline is automatically updated every preset period, taking into account terminal firmware upgrades and changes in business scenarios.

[0009] Furthermore, the evaluation of the terminal behavior baseline based on dynamic indicators and evaluation thresholds includes: The system collects indicator data from the minimum necessary evaluation set in real time, and adjusts the evaluation threshold based on a dynamic adaptation factor. The adjustment formula includes: θ i,t =θ i,0 ×Wi' Where, θ i,t Let θ be the evaluation threshold for the i-th indicator at time t; i,0 The basic threshold for indicator i; Compare the measured value of the indicator with the dynamic threshold θ i,t Compared with the baseline range of terminal behavior, when the measured value of the indicator is within the baseline range and the measured value of the indicator is ≤θ i,t It was determined to be compliant. If the measured value of the indicator exceeds the baseline range but the measured value of the indicator is ≤θ i,t It was determined to be an early warning. If the measured value of the indicator is greater than θ i,t This was deemed a violation.

[0010] Furthermore, the optimization of terminal communication includes: An improved BiLSTM model is used to perform redundancy calculations on the collaborative architecture topology diagram in combination with the characteristics of the scenario business. Based on the calculation results and resource constraints, the network structure is pruned to achieve communication structure optimization. At the same time, optimization suggestions are provided based on the specific business scenarios, and the optimization suggestions are quantitatively evaluated and the optimization effects are verified.

[0011] Furthermore, after optimizing the terminal communication, risk correlation analysis will be performed on the terminal resource data based on the indicator correlation logic, and the weight of the evaluation indicators will be optimized according to the results of the risk correlation analysis. Establish a resource conflict resolution mechanism, generate task avoidance strategies when evaluation tasks conflict with control instructions based on monitoring results, and schedule lightweight evaluation tasks with priority.

[0012] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the content of the lightweight assessment method for network security level protection applicable to Internet of Things scenarios as described above.

[0013] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the content of the lightweight assessment method for network security level protection applicable to Internet of Things scenarios as described above.

[0014] Compared to existing technologies, the beneficial effects of this application are as follows: (1) This application integrates basic security level protection indicators, scenario-specific indicators and dynamic adaptation factors by constructing a dynamic indicator library. It combines the common characteristics of new energy Internet of Things devices, demand differences and terminal types to generate indicator screening principles and correlation logic. It can dynamically adjust the indicator weights and evaluation thresholds according to risk level, business period and equipment resource status. At the same time, it selects the minimum necessary evaluation set so that the evaluation results fit the actual security needs of different scenarios and accurately identify the security risks of different scenarios of new energy Internet of Things. (2) This application conducts lightweight evaluation based on terminal behavior baseline modeling, avoiding the high resource consumption caused by full index evaluation, and adapting to the constraints of limited computing power and power consumption sensitivity of new energy IoT terminals, ensuring that the evaluation process does not affect the normal business operation of the terminal and improving the real-time response capability of the evaluation. (3) This application adopts an improved BiLSTM model combined with the characteristics of scenario services to perform redundant calculations and network structure trimming on the collaborative architecture topology diagram. At the same time, it provides scenario-based optimization suggestions and quantitatively evaluates the effect. After optimization, risk correlation analysis is carried out based on the indicator correlation logic to further optimize the indicator weights, effectively prevent security risks such as client vulnerabilities, data leakage, and illegal control of devices, and improve terminal communication security and data transmission efficiency. Attached Figure Description

[0015] In the attached diagram: Figure 1 This is a schematic diagram of the method steps in an embodiment of this application. Detailed Implementation

[0016] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of this application, but not all embodiments. Generally, the components of the embodiments of this application described and shown in the accompanying drawings can be arranged and designed in various different configurations. Example 1

[0017] like Figure 1 As shown, a lightweight assessment method for network security level protection applicable to IoT scenarios includes: Establish a dynamic indicator database to acquire, organize, and analyze the common characteristics, demand differences, terminal types, and resource constraints of new energy IoT devices in different application scenarios; The indicator hierarchy is divided according to basic security level protection indicators, scenario-specific indicators and dynamic adaptation factors. Indicator selection principles are generated based on common characteristics, demand differences and terminal types. Indicator association logic is generated by combining indicator hierarchy and indicator selection principles. The basic cybersecurity level protection indicators are generated based on Cybersecurity Level Protection 2.0, which is the Cybersecurity Level Protection 2.0 standard. Scenario-specific indicators are extracted for different application scenarios of the new energy Internet of Things. The dynamic adaptation factor is an adaptation factor for risk level, business period, and equipment resource status. It dynamically adjusts indicator weights and evaluation thresholds based on an indicator weight adjustment algorithm. The calculation formula for the dynamic adaptation factor is as follows: Wi' = Wi*(α*R+β*T+γ*S) Wherein, Wi' is the current dynamic adaptation factor, Wi is the previous dynamic adaptation factor, R is the risk factor, which is dynamically adjusted according to the frequency of each risk level in history, T is the time period factor, which is adjusted according to the business peak and trough periods, S is the resource status factor, which is adjusted according to the occupancy rate of each hardware in the IoT terminal, and α, β and γ are the normalization coefficients of each factor, which are configured according to the scenario.

[0018] S=C used / C total +M used / M total +P remaining / P total Among them, C used / C total M represents the real-time computing power utilization rate. used / M total For real-time memory usage, P remaining / P total This represents the percentage of remaining battery power.

[0019] The generation of indicator association logic involves establishing a dependency and conflict relationship graph between indicators based on the terminal type and the current resource status factor S. Specific steps include: Calculate the information entropy of each indicator, determine the indicator discrimination, determine the initial weight of the indicator by combining the analytic hierarchy process, and dynamically adjust the screening threshold according to the current resource status factor. A minimum necessary evaluation set is selected from the dynamic indicator library based on the indicator discrimination, the initial weight of the indicator, and the screening threshold. The number of indicators in the evaluation set is less than or equal to the preset number threshold. By combining the minimum necessary evaluation set, an adjacency matrix is ​​used to represent the binary relationship graph of dependency and conflict between indicators.

[0020] Establish a collaborative architecture topology based on the connection relationship between IoT terminals and server platforms, monitor IoT terminals in real time, and obtain terminal resource data of IoT terminals. The collaborative architecture topology diagram is created by using cross-protocol adaptation interfaces to uniformly parse the communication protocols between IoT terminals and the platform, perform lightweight protocol conversion, and then draw a collaborative architecture topology diagram that includes terminal nodes, communication links, and data flow.

[0021] Establish a cross-scenario lightweight evaluation model, conduct lightweight evaluation of the collaborative architecture topology based on terminal resource data, and optimize terminal communication based on the lightweight evaluation results; Lightweight evaluation involves modeling terminal behavior baselines that match each IoT terminal, including: The core behavioral characteristics of the data acquisition terminal during normal operation are used as baseline characteristics. An improved K-means clustering algorithm is used to cluster baseline features to generate a baseline range for normal behavior. The baseline of terminal behavior is evaluated based on dynamic indicators and evaluation thresholds; The baseline is automatically updated every preset period, taking into account terminal firmware upgrades and changes in business scenarios.

[0022] The evaluation of the terminal behavior baseline based on dynamic indicators and evaluation thresholds includes: The system collects indicator data from the minimum necessary evaluation set in real time, and adjusts the evaluation threshold based on a dynamic adaptation factor. The adjustment formula includes: θ i,t =θ i,0 ×Wi' Where, θ i,t Let θ be the evaluation threshold for the i-th indicator at time t; i,0 The basic threshold for indicator i; Compare the measured value of the indicator with the dynamic threshold θ i,t Compared with the baseline range of terminal behavior, when the measured value of the indicator is within the baseline range and the measured value of the indicator is ≤θ i,t It was determined to be compliant. If the measured value of the indicator exceeds the baseline range but the measured value of the indicator is ≤θ i,t It was determined to be an early warning. If the measured value of the indicator is greater than θ i,t This was deemed a violation.

[0023] Optimizing terminal communication includes: An improved BiLSTM model is used to perform redundancy calculations on the collaborative architecture topology diagram in combination with the characteristics of the scenario business. Based on the calculation results and resource constraints, the network structure is pruned to achieve communication structure optimization. At the same time, optimization suggestions are provided based on the specific business scenarios, and the optimization suggestions are quantitatively evaluated and the optimization effects are verified.

[0024] After optimizing terminal communication, risk correlation analysis will be performed on terminal resource data based on indicator correlation logic, and the weight of evaluation indicators will be optimized based on the results of the risk correlation analysis. Establish a resource conflict resolution mechanism, generate task avoidance strategies when evaluation tasks conflict with control instructions based on monitoring results, and schedule lightweight evaluation tasks with priority. Example 2

[0025] First, a dynamic indicator database is established to acquire, organize, and analyze the common characteristics, demand differences, terminal types, and resource constraints of new energy IoT devices in different application scenarios. As one implementation method, the characteristics, demands, types, and resource constraints of new energy IoT devices in specific application scenarios can be collected and organized all at once through manual surveys and expert experience, and then solidified into a static indicator database. As another implementation method, the operating data of new energy IoT devices can be batch-processed through periodic data collection and analysis to update some of the contents of the indicator database.

[0026] The indicator hierarchy is divided based on basic compliance indicators, scenario-specific indicators, and dynamic adaptation factors. Indicator selection principles are generated based on common characteristics, differences in needs, and terminal types. The indicator hierarchy and selection principles are combined to generate indicator association logic. For example, a fixed indicator hierarchy structure can be pre-defined, and indicator selection principles can be generated based on general rules. Then, the association logic between indicators can be established through manual configuration or preset templates. Alternatively, a series of rules based on expert knowledge can be defined to automatically derive the indicator hierarchy, selection principles, and association logic based on the input basic compliance indicators, scenario-specific indicators, and dynamic adaptation factors.

[0027] A collaborative architecture topology diagram is established based on the connection relationship between IoT terminals and the server platform. The IoT terminals are monitored in real time to obtain terminal resource data. The collaborative architecture topology diagram can be established by manually drawing or importing a preset network topology diagram. The IoT terminals are monitored in a periodic polling manner to obtain terminal resource data. As a preferred implementation method, a lightweight agent program can also be deployed on the IoT terminals. The agent program collects terminal resource data at regular intervals and reports it to the server platform through a standard protocol. The server platform automatically builds or updates the collaborative architecture topology diagram based on the reported data.

[0028] Based on this, a cross-scenario lightweight evaluation model is established. This model performs lightweight evaluation of the collaborative architecture topology based on terminal resource data. According to the evaluation results, terminal communication is optimized. A simple evaluation model based on preset thresholds can be established; when terminal resource data exceeds the threshold, it is marked as abnormal, and operations personnel manually analyze the evaluation results and propose communication optimization suggestions. Alternatively, a statistical analysis-based evaluation model can be established. By analyzing historical terminal resource data, potential security risks are identified, and terminal communication is adjusted according to preset optimization rules.

[0029] This application establishes a dynamic indicator library and combines scenario-specific indicators and dynamic adaptation factors to achieve flexible adjustment and scenario adaptation of evaluation indicators. By constructing indicator hierarchies, screening principles, and correlation logic, and adopting a cross-scenario lightweight evaluation model, it effectively reduces resource consumption in the evaluation process and improves real-time performance. At the same time, by establishing a collaborative architecture topology diagram and monitoring terminal resource data in real time, it comprehensively grasps the connection and data flow between the terminal and the platform, and optimizes terminal communication based on the evaluation results. Thus, it provides a precise and efficient network security level protection evaluation and optimization solution for new energy IoT devices. Example 3

[0030] The Cybersecurity Classified Protection 2.0 standard is a network security level protection standard. The scenario-specific indicators are extracted for different application scenarios of the new energy Internet of Things. The dynamic adaptation factors are adaptation factors for risk level, business time period and equipment resource status. The indicator weights and evaluation thresholds are dynamically adjusted according to the indicator weight adjustment algorithm.

[0031] Specifically, the basic cybersecurity classification protection indicators are the cornerstone of cybersecurity classification protection assessments. They are generated based on authoritative standards issued by the state or industry and are important norms in China's cybersecurity field, providing detailed security requirements and assessment methods for information systems of different security levels. By linking the basic indicators with the Cybersecurity Classified Protection 2.0 standard, and by analyzing the various control points, requirements, and assessment indicators in the standard, these indicators are structured, digitized, and imported into a dynamic indicator library. For example, a database can be established to store the specific requirements of Cybersecurity Classified Protection 2.0 regarding physical security, network security, host security, application security, and data security, and initial weights and evaluation thresholds can be assigned to each requirement.

[0032] Scenario-specific indicators are designed to compensate for the shortcomings of general security compliance indicators in specific application scenarios. New energy IoT scenarios have their own unique characteristics, such as wind power generation, photovoltaic power plants, and energy storage systems. These scenarios have special requirements for real-time performance, reliability, data integrity, and physical security protection. Extracting scenario-specific indicators involves in-depth analysis of the business processes, data flows, equipment characteristics, potential threats, and security needs of these specific scenarios to identify highly targeted security assessment indicators applicable only to that scenario. This is done through methods such as expert interviews, risk assessments, industry standard analysis, and historical security incident reviews. For example, for wind power generation scenarios, specific indicators such as "communication encryption strength of the wind turbine control system," "remote operation and maintenance channel authentication mechanism," and "data integrity of blade icing sensor" can be extracted. These indicators can more accurately reflect the security risks of specific scenarios.

[0033] Dynamic adaptation factors are key to achieving lightweight and dynamic assessments. In the IoT environment, security risks, business needs, and device status are constantly changing. Risk level adaptation factors refer to dynamically adjusting the weights of assessment indicators based on factors such as the current threat landscape, vulnerability status, and historical attack events faced by the system. For example, when a zero-day vulnerability targeting a certain IoT device is detected, the weight of assessment indicators related to that vulnerability should be immediately increased. Business time period adaptation factors take into account that IoT businesses may have different importance or activity levels at different times. For example, during nighttime or off-peak production periods, the assessment weights of certain non-core businesses can be appropriately reduced, while the assessment weights of core businesses remain unchanged or are increased. Device resource status adaptation factors refer to dynamically adjusting the depth and frequency of assessments based on resource limitations such as CPU utilization, memory usage, network bandwidth, and power consumption of IoT terminals.

[0034] For example, when terminal resources are scarce, the evaluation of key indicators can be prioritized, while the evaluation of secondary indicators can be postponed or simplified. The indicator weight adjustment algorithm is a core mechanism used to adjust the importance and judgment criteria of each evaluation indicator in real time based on the above dynamic adaptation factors.

[0035] Through the above technical solutions, this application can construct a lightweight evaluation index system that conforms to national standards, is highly adaptable to specific scenarios, and can be dynamically adjusted. This significantly improves the accuracy, real-time performance, and resource utilization efficiency of the evaluation, ensuring that effective security level protection evaluations can be conducted in resource-constrained IoT environments without affecting business operations. Example 4

[0036] Based on the terminal type and current resource status factors, a minimum necessary evaluation set is selected from the dynamic indicator library, and a dependency and conflict relationship diagram between indicators is established based on the minimum necessary evaluation set.

[0037] The generation of the indicator association logic involves selecting a minimum necessary set of evaluation criteria from a dynamic indicator library based on the terminal type and current resource status factors. The terminal type refers to the specific classification of IoT terminals, such as sensors, actuators, gateways, and edge computing devices. Different types of terminals have different functions, security requirements, and resource limitations. For example, a simple temperature sensor may only need to focus on data integrity and communication encryption indicators, while a smart camera may need to focus on more complex indicators such as video stream privacy, firmware integrity, and access control.

[0038] When selecting the minimum necessary evaluation set, the system will initially filter out indicators irrelevant to the terminal type based on the preset terminal type-indicator mapping rules. Current resource status factors reflect the operating status and available resources of the IoT terminal at a specific moment, such as CPU utilization, memory usage, battery level, network bandwidth, and storage space. These factors directly affect the terminal's ability and efficiency in performing evaluation tasks. When the terminal's battery level is low or the CPU load is high, evaluation indicators with low resource consumption should be prioritized, or high-resource-consumption evaluation tasks should be postponed.

[0039] Resource status factors can be collected in real time through the terminal's built-in monitoring module and reported periodically to the evaluation system.

[0040] The dynamic indicator library is a collection of all possible evaluation indicators. These indicators have been organized and classified, and may include metadata such as resource consumption, evaluation duration, and applicable scenarios. The process of selecting a minimum necessary set of indicators aims to intelligently select the minimum set of indicators from the dynamic indicator library that is sufficient to meet the security evaluation requirements for a specific terminal under a specific state.

[0041] The screening logic comprehensively considers the functional safety requirements determined by the terminal type and the execution capability determined by the current resource status factor S. For example, for a resource-constrained terminal, even if a certain indicator is functionally relevant, it may be excluded or replaced with an equivalent lightweight indicator if its resource consumption is too high. The screening process can be implemented using rule-based expert systems, machine learning models, or optimization algorithms to ensure the "minimum" and "necessary" nature of the evaluation set.

[0042] Based on this, a dependency and conflict relationship graph is established between indicators according to the minimum necessary evaluation set. The dependency relationship between indicators refers to the fact that the execution or result of some evaluation indicators depends on other indicators. For example, before performing data integrity verification, it may be necessary to complete the check of communication encryption configuration. This dependency relationship ensures the logical order and validity of the evaluation. If the dependent indicator fails, the subsequent dependent indicators may not need to be executed or the execution strategy needs to be adjusted. The conflict relationship between indicators refers to the mutual exclusion or resource competition between some evaluation indicators in execution. For example, executing two high CPU-consuming encryption algorithm strength tests at the same time may cause the terminal to crash or the evaluation results to be distorted. The configuration of some security policies may have logical conflicts with other policies. Establishing a conflict relationship graph helps to avoid these problems when scheduling evaluation tasks and ensures the stability and accuracy of the evaluation process.

[0043] Through the above technical solution, this application can intelligently select the most concise and necessary set of evaluation indicators from the dynamic indicator library according to the specific type of IoT terminal and its real-time resource status. This effectively solves the problems of indicator generalization and resource waste in traditional evaluation methods, significantly reduces the evaluation cost of a single terminal, and improves the relevance and efficiency of the evaluation. By establishing a dependency and conflict relationship diagram between indicators, the evaluation system can more accurately plan the execution order of evaluation tasks, avoid redundancy and conflicts, and ensure the logical rigor of the evaluation process and the rationality of resource utilization. Example 5

[0044] The collaborative architecture topology diagram is created by using cross-protocol adaptation interfaces to uniformly parse the communication protocols between IoT terminals and the platform, perform lightweight protocol conversion, and then draw a collaborative architecture topology diagram that includes terminal nodes, communication links, and data flow.

[0045] Cross-protocol adapter interfaces are designed to solve the problem of heterogeneous protocol communication in IoT environments. They provide a unified interface that enables data from different protocols to be parsed and processed. This interface can be a software module or a hardware device with built-in protocol parsers that can identify and convert protocols used by different terminals and platforms. It is responsible for protocol encapsulation and decapsulation during data transmission to ensure data format consistency.

[0046] Unified parsing of communication protocols between IoT terminals and platforms refers to the process by which the cross-protocol adapter interface, after receiving a data stream from an IoT terminal or platform, determines the protocol type based on a preset protocol identification mechanism and calls the corresponding parsing module to perform deep parsing of the data packets, extracting key information such as the communicating parties, data content, and timestamps. This ensures that all communication data can be understood and processed, laying the foundation for subsequent lightweight protocol conversion and topology mapping.

[0047] Protocol lightweighting involves transforming raw, potentially redundant, or complex protocol data into a lightweight, standardized internal representation based on unified parsing. This can be achieved by removing unnecessary fields from the protocol header, compressing data content, or mapping control messages of a specific protocol to a unified event type. The aim is to retain core communication information while reducing data volume and processing complexity.

[0048] The final collaborative architecture topology diagram, including terminal nodes, communication links, and data flow, is drawn based on standardized communication data obtained after lightweight protocol conversion. The system identifies all IoT terminals in the network as terminal nodes, identifies the data transmission path between the terminal and the platform as the communication link, and determines the data flow based on the source and destination addresses of the data packets. This information is organized into a graph structure and displayed through a graphical interface, intuitively and accurately showing the structure and data flow of the IoT network, providing a visual foundation for subsequent lightweight evaluation.

[0049] Through the above technical solution, this application can effectively solve the compatibility problem caused by the diversity of protocols in the Internet of Things (IoT) environment. This enables the established collaborative architecture topology diagram to accurately and comprehensively reflect the real connection relationship, communication links, and data flow between terminals and platforms of different protocol types, avoiding the loss or error of topology diagram information due to protocol incompatibility or incomplete parsing. This provides a more solid and accurate basis for terminal communication optimization, significantly improving the applicability and effectiveness of the lightweight assessment method for network security level protection. Example 6

[0050] Lightweight evaluation involves generating a terminal behavior baseline that matches each IoT terminal for modeling, and then evaluating the terminal behavior baseline based on dynamic indicators and evaluation thresholds.

[0051] Modeling involves generating a terminal behavior baseline that matches each IoT terminal, aiming to establish a unique "fingerprint" for each terminal. This fingerprint describes its normal communication patterns, resource usage, and function call sequences in specific scenarios. The modeling process may include collecting historical data from the terminal over a period of time, such as CPU utilization, memory usage, network traffic, process activity, and API calls. Statistical methods, machine learning algorithms, or rule engines are then used to extract stable and distinguishable features, forming a profile of the terminal's normal behavior. By establishing independent baselines for each terminal, the challenges of a wide variety of IoT devices with diverse functions and behavioral patterns can be effectively addressed, avoiding false positives or false negatives caused by a "one-size-fits-all" evaluation method.

[0052] Evaluating the terminal behavior baseline involves comparing the real-time behavior data of IoT terminals with a pre-established baseline, and then making a judgment based on dynamic indicators and evaluation thresholds. For example, when a terminal's real-time network traffic deviates significantly from its baseline range and exceeds a dynamically adjusted evaluation threshold, it may be judged as abnormal behavior.

[0053] Through the above technical solution, lightweight evaluation no longer relies solely on static terminal resource data. Instead, it generates a terminal behavior baseline that matches the characteristics of each IoT terminal for modeling. When the real-time behavior of the terminal deviates from its baseline and exceeds the dynamically adjusted evaluation threshold, the system can identify abnormal behavior or potential security risks in a timely and accurate manner. This improves the accuracy and effectiveness of lightweight evaluation, reduces false alarm and false negative rates, and thus more reliably protects the network security of IoT terminals, providing a more solid data foundation for subsequent terminal communication optimization. Example 7

[0054] To optimize terminal communication, an improved BiLSTM model is used to perform redundancy calculations on the collaborative architecture topology diagram based on scenario service characteristics. The network structure is then pruned according to the calculation results and resource constraints to achieve communication structure optimization. At the same time, optimization suggestions are provided in conjunction with scenario services, the optimization suggestions are quantitatively evaluated, and the optimization effect is verified and evaluated.

[0055] When optimizing terminal communication, an improved BiLSTM model is first used to perform redundancy calculations on the collaborative architecture topology diagram, taking into account the characteristics of the scenario's business. By analyzing the terminal nodes, communication links, and data flow in the collaborative architecture topology diagram, the inherent laws of communication modes and data transmission can be deeply explored. During redundancy calculations, the model fully considers the characteristics of the scenario's business, including data transmission frequency, data volume, real-time requirements, security requirements, and device interaction modes for specific IoT application scenarios. For services with extremely high real-time requirements, even if there is a small amount of duplicate data transmission, the model may judge it as necessary rather than redundant. For non-real-time data, a more stringent redundancy identification is performed, including path redundancy, data redundancy, functional redundancy, or unnecessary connections.

[0056] Based on the above redundancy calculation results and taking into full account the resource constraints of IoT terminals, network structure is trimmed to optimize the communication structure.

[0057] Resource constraints refer to the limitations of IoT terminals in terms of computing power, storage space, battery life, network bandwidth, and communication latency. When pruning the network structure, the system will make fine adjustments to the collaborative architecture topology based on the redundancy information identified by the improved BiLSTM model. This may include deleting redundant communication links, merging duplicate data streams, adjusting data routing strategies, shutting down unnecessary ports or services, and optimizing packet size or transmission frequency. All pruning operations strictly follow resource constraints to ensure that the optimized network structure can still meet the normal operation of terminals and various business needs while improving communication efficiency and reducing energy consumption, avoiding critical business interruption or terminal resource exhaustion due to over-optimization.

[0058] Based on this, this application will also provide optimization suggestions in combination with specific scenario business. The optimization suggestions are based on the results of redundant calculation and network structure tailoring, and are customized for specific IoT application scenarios. They are highly targeted and operable. For example, the system may suggest adjusting the data reporting frequency of certain terminals, recommend upgrading the firmware of specific devices to support more efficient communication protocols, or propose adjusting the network segmentation strategy to optimize the data transmission path.

[0059] To ensure the effectiveness of the optimization recommendations, this application will conduct a quantitative evaluation of these recommendations. The quantitative evaluation is usually carried out through simulation, modeling or small-scale experiments. Evaluation indicators may include percentage reduction in communication latency, reduction in energy consumption, change in bandwidth utilization, data transmission success rate and degree of reduction in security risks, so that the optimization effect can be measured and compared.

[0060] Finally, in the actual deployment or testing environment, the system will execute the optimization suggestions and conduct another lightweight evaluation. The evaluation results before and after optimization will be compared to verify whether the evaluation optimization effect has achieved the expected results, thus forming a continuous improvement optimization loop.

[0061] By employing the above technical solution and combining an improved BiLSTM model with scenario-specific business characteristics to perform redundancy calculations on the collaborative architecture topology, this application can accurately identify redundant communication paths and unnecessary data transmissions in IoT networks. This effectively avoids the problem of insufficient optimization in complex IoT environments using traditional methods. Based on this calculation result and fully considering the resource constraints of IoT terminals, a refined network structure is tailored, thereby achieving significant optimization of the communication structure. This greatly improves communication efficiency, reduces energy consumption, and effectively saves valuable terminal resources. Customized optimization suggestions are provided in conjunction with specific scenario-specific business requirements. Through quantitative evaluation and effect verification, the effectiveness and operability of the optimization scheme are ensured. Example 8

[0062] From a hardware perspective, this application provides an embodiment of an electronic device containing all or part of a lightweight assessment method for network security level protection applicable to IoT scenarios. The electronic device includes a service processor and a distributed memory. The service processor is connected to the memory, and the distributed memory stores a service self-management program configured to store machine-readable instructions. The service processor executes the service self-management program, and when the instructions are executed by the processor, the lightweight assessment method for network security level protection applicable to IoT scenarios described above can be implemented. Example 9

[0063] Embodiments of this application also provide a computer-readable storage medium capable of implementing the lightweight assessment method for network security level protection applicable to IoT scenarios, where the execution subject is a server or client as described in the above embodiments. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements all the contents of the lightweight assessment method for network security level protection applicable to IoT scenarios, where the execution subject is a server or client as described in the above embodiments.

[0064] The embodiments described above are merely preferred embodiments of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications, improvements, and substitutions without departing from the concept of this application, and these all fall within the protection scope of this application.

Claims

1. A lightweight assessment method for network security level protection applicable to IoT scenarios, characterized in that, include: Establish a dynamic indicator database to acquire, organize, and analyze the common characteristics, demand differences, terminal types, and resource constraints of new energy IoT devices in different application scenarios; The indicator hierarchy is divided according to basic security level protection indicators, scenario-specific indicators and dynamic adaptation factors. Indicator selection principles are generated based on common characteristics, demand differences and terminal types. Indicator association logic is generated by combining indicator hierarchy and indicator selection principles. Establish a collaborative architecture topology based on the connection relationship between IoT terminals and server platforms, monitor IoT terminals in real time, and obtain terminal resource data of IoT terminals. Establish a cross-scenario lightweight evaluation model, conduct lightweight evaluation of the collaborative architecture topology based on terminal resource data, and optimize terminal communication based on the lightweight evaluation results.

2. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 1, characterized in that, The basic compliance indicators are generated based on the Compliance Standard 2.0, which is the network security level protection standard 2.

0. Scenario-specific indicators are extracted for different application scenarios of the new energy Internet of Things. The dynamic adaptation factor is an adaptation factor for risk level, business period, and equipment resource status. It dynamically adjusts indicator weights and evaluation thresholds based on an indicator weight adjustment algorithm. The calculation formula for the dynamic adaptation factor is as follows: Wi' = Wi*(α*R+β*T+γ*S) Wherein, Wi' is the current dynamic adaptation factor, Wi is the previous dynamic adaptation factor, R is the risk factor, which is dynamically adjusted according to the frequency of each risk level in history, T is the time period factor, which is adjusted according to the business peak and trough periods, S is the resource status factor, which is adjusted according to the occupancy rate of each hardware in the IoT terminal, and α, β and γ are the normalization coefficients of each factor, which are configured according to the scenario.

3. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 2, characterized in that, The generation of the indicator association logic involves establishing a dependency and conflict relationship graph between indicators based on the terminal type and the current resource status factor S. Specific steps include: Calculate the information entropy of each indicator, determine the indicator discrimination, determine the initial weight of the indicator by combining the analytic hierarchy process, and dynamically adjust the screening threshold according to the current resource status factor. A minimum necessary evaluation set is selected from the dynamic indicator library based on the indicator discrimination, the initial weight of the indicator, and the screening threshold. The number of indicators in the evaluation set is less than or equal to the preset number threshold. By combining the minimum necessary evaluation set, an adjacency matrix is ​​used to represent the binary relationship graph of dependency and conflict between indicators.

4. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 2, characterized in that, The collaborative architecture topology diagram is created by using a cross-protocol adaptation interface to uniformly parse the communication protocols between IoT terminals and the platform, perform lightweight protocol conversion, and then draw a collaborative architecture topology diagram including terminal nodes, communication links, and data flow.

5. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 2, characterized in that, The lightweight evaluation involves modeling terminal behavior baselines that match each IoT terminal, including: The core behavioral characteristics of the data acquisition terminal during normal operation are used as baseline characteristics. An improved K-means clustering algorithm is used to cluster baseline features to generate a baseline range for normal behavior. The baseline of terminal behavior is evaluated based on dynamic indicators and evaluation thresholds; The baseline is automatically updated every preset period, taking into account terminal firmware upgrades and changes in business scenarios.

6. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 5, characterized in that, The evaluation of the terminal behavior baseline based on dynamic indicators and evaluation thresholds includes: The system collects indicator data from the minimum necessary evaluation set in real time, and adjusts the evaluation threshold based on a dynamic adaptation factor. The adjustment formula includes: i i,t =θ i,0 ×Wi' Where, θ i,t Let θ be the evaluation threshold for the i-th indicator at time t; i,0 The basic threshold for indicator i; Compare the measured value of the indicator with the dynamic threshold θ i,t Compared with the baseline range of terminal behavior, when the measured value of the indicator is within the baseline range and the measured value of the indicator is ≤θ i,t It was determined to be compliant. If the measured value of the indicator exceeds the baseline range but the measured value of the indicator is ≤θ i,t It was determined to be an early warning. If the measured value of the indicator is greater than θ i,t This was deemed a violation.

7. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 6, characterized in that, The optimization of terminal communication includes: An improved BiLSTM model is used to perform redundancy calculations on the collaborative architecture topology diagram in combination with the characteristics of the scenario business. Based on the calculation results and resource constraints, the network structure is pruned to achieve communication structure optimization. At the same time, optimization suggestions are provided based on the specific business scenarios, and the optimization suggestions are quantitatively evaluated and the optimization effects are verified.

8. The lightweight assessment method for network security level protection applicable to IoT scenarios according to claim 7, characterized in that, After optimizing terminal communication, risk correlation analysis will be performed on terminal resource data based on indicator correlation logic, and the weight of evaluation indicators will be optimized based on the results of the risk correlation analysis. Establish a resource conflict resolution mechanism, generate task avoidance strategies when evaluation tasks conflict with control instructions based on monitoring results, and schedule lightweight evaluation tasks with priority.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the content of the lightweight evaluation method for network security level protection applicable to Internet of Things scenarios as described in claim 1.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the content of the lightweight evaluation method for network security level protection applicable to the Internet of Things scenario as described in claim 1.