An intelligent risk perception and linkage protection system for internet of things terminals
Patent Information
- Application Number
- CN202611044114.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-09-11
AI Technical Summary
上述方案在简单攻击或单点异常场景下具有一定效果,但在多终端协同、跨网关传播、业务链路级联异常等复杂场景中,仍然存在明显不足
本发明通过采集运行指纹、通信会话指纹、可信校验指纹和场景一致性指纹,并将各指纹时间序列构建为终端连续风险控制路径,能够同时表征终端资源占用、进程端口变化、通信异常、可信状态下降以及传感器状态与控制动作之间的不一致关系。相比仅依赖单一流量阈值、日志告警或静态规则的检测方式,本发明能够刻画终端风险由正常状态向异常状态演化的连续过程,提高对隐蔽性攻击、固件篡改、异常控制和渐进式风险累积的识别准确性。
Smart Images

Figure CN122741202A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) security technology, and more specifically to an intelligent risk perception and linkage protection system for IoT terminals. Background Technology
[0002] With the widespread application of IoT technology in smart parks, smart manufacturing, smart homes, smart energy, smart transportation, and public safety, a large number of heterogeneous devices, such as cameras, access controllers, sensors, smart meters, edge gateways, and industrial control terminals, are continuously connecting to the network. IoT terminals are typically characterized by their large number, complex types, dispersed deployment, limited computing power, inconsistent firmware versions, and diverse communication protocols. Their security status is not only affected by network attacks but also by a combination of factors, including device aging, environmental disturbances, configuration changes, invalid identity credentials, firmware tampering, and abnormal business calls. Therefore, timely, accurate, and continuous risk perception of IoT terminals and coordinated protection before risks spread have become crucial issues in IoT security management.
[0003] Existing IoT security solutions typically rely on gateway-side traffic monitoring, terminal log analysis, rule-based threshold alarms, or single-device anomaly detection to identify risks. For example, they identify suspected abnormal devices by judging whether a terminal has abnormal external connections, sudden traffic surges, excessive login failures, or abnormally open ports; or they block, isolate, or notify administrators of abnormal terminals through preset blacklists, access control policies, and fixed alarm rules. These solutions are effective in simple attack or single-point anomaly scenarios, but they still have significant shortcomings in complex scenarios such as multi-terminal collaboration, cross-gateway propagation, and cascading anomalies in business links.
[0004] First, existing solutions typically treat terminal risks as discrete, static anomalies, failing to capture the continuous evolution of terminal operating states, communication behaviors, trusted verification results, and scenario consistency over time. IoT terminal risks are often not instantaneous but manifest as continuous shifts in multiple dimensions, such as abnormal resource usage, changes in communication targets, accumulated authentication failures, decreased firmware trustworthiness, and inconsistencies between sensor data and control actions. Using only single-moment thresholds for judgment can easily lead to false alarms or missed alarms.
[0005] Secondly, most existing solutions take a single terminal or the connection relationship between two devices as the analysis object, and lack the modeling capability for the group risk propagation relationship formed by communication session links, service call links and physical adjacent areas. In actual Internet of Things scenarios, an abnormal terminal may affect multiple devices through the same communication session, induce control anomalies along service call links, or form environment-related linkage anomalies in the same area. Traditional graph structures can usually only describe the relationship between two nodes, and it is difficult to accurately characterize one-to-many and many-to-many risk propagation patterns.
[0006] Thirdly, existing risk source localization usually relies on the sequence of alarm times or manual experience judgment. When multiple terminals have anomalies at approximately the same time, it is difficult to distinguish the initial risk source, affected nodes and concomitant abnormal nodes, resulting in a lack of pertinence in disposal strategies. If isolation, network disconnection or rollback operations are directly performed on all abnormal terminals, key service interruption may be caused; if the disposal intensity is insufficient, the risk may continue to spread. In addition, existing protection strategies are mostly triggered by fixed rules, and lack the ability to dynamically adjust according to risk propagation intensity, terminal service importance, service continuity constraints and disposal effects. After the protection action is executed, the system usually only records the disposal result, and it is difficult to reversely correct the risk propagation relationship and subsequent protection actions according to the change of risk residual, resulting in the lack of closed-loop linkage between risk perception and protection decision-making.
[0007] Therefore, there is an urgent need for an intelligent risk perception and linkage protection system that can fuse multi-dimensional fingerprint information of Internet of Things terminals, characterize the continuous risk evolution process, identify cross-terminal risk propagation relationships, and generate linkage protection actions under the premise of satisfying service continuity constraints. Summary of the Invention
[0008] To solve the above technical problems, the present invention discloses an intelligent risk perception and linkage protection system for Internet of Things terminals. The system collects terminal operation fingerprints, communication session fingerprints, trusted verification fingerprints and scene consistency fingerprints within a preset time window, constructs a terminal continuous risk control path, and inputs the path into a neural controlled differential equation encoder to generate risk trajectory states; taking terminals and edge gateways as nodes, a trusted gated temporal risk hypergraph is constructed based on communication session links, service call links and physical adjacent areas; the risk trajectory states are matched with abnormal prototypes including normal operation, trusted attenuation, horizontal propagation and environment induction through entropy-regularized optimal transport to determine risk source nodes and affected nodes; then hierarchical linkage protection actions are generated in combination with service continuity constraints, and the risk hypergraph and subsequent actions are corrected based on risk residuals. The present invention improves the accuracy of group risk identification, risk source localization and linkage protection.
[0009] An intelligent risk perception and linkage protection system for Internet of Things terminals, comprising: The data acquisition unit collects the operation fingerprint, communication session fingerprint, trusted verification fingerprint and scenario consistency fingerprint of each IoT terminal in a preset time window, and constructs a continuous risk control path for the terminal based on the time sequence of each fingerprint. The risk trajectory state generation unit inputs the continuous risk control path of the terminal into the neural controlled differential equation encoder to obtain the risk trajectory state of each Internet of Things terminal. The Trusted Gated Temporal Risk Hypergraph Generation Unit uses IoT terminals and edge gateways as nodes to construct communication session hyperedges, service call hyperedges, and spatial proximity hyperedges based on the same communication session link, the same service call link, and the same physical proximity area, respectively, to generate a Trusted Gated Temporal Risk Hypergraph, and configures hyperedge propagation strength and trusted gated weights for each hyperedge. The risk propagation and localization unit performs entropy-normalized optimal transmission matching between the risk trajectory state and preset normal operation prototype, trusted attenuation prototype, lateral propagation prototype and environmentally induced anomaly prototype, and determines the risk source node, risk propagation superedge and affected node based on the matching cost, superedge propagation strength and trusted gating weight. The decision control unit generates at least two levels of linked protection actions for the risk source node and the affected node, respectively, based on the risk source node, risk propagation hyperedge, affected node, and business continuity constraints. It also corrects the trusted gating time-series risk hypergraph and subsequent linked protection actions based on the risk residual changes after the actions are executed.
[0010] Preferably, the runtime fingerprint includes at least three of the following: process startup changes, port opening changes, processor utilization changes, memory utilization changes, and peripheral call changes; the communication session fingerprint includes at least three of the following: communication object, protocol port, packet length distribution, uplink and downlink traffic mutations, cross-network segment access counts, and authentication failure counts; the trusted verification fingerprint includes at least two of the following: device certificate status, startup chain hash verification result, firmware hash verification result, and security patch version status; and the scenario consistency fingerprint includes the matching relationship between the sensor's measured environmental status, terminal control actions, control action triggering conditions, and the direction of environmental status changes.
[0011] Preferably, constructing a continuous risk control path for the terminal includes: normalizing the operation fingerprint, communication session fingerprint, trusted verification fingerprint, and scenario consistency fingerprint respectively; calculating the abnormal residuals of each fingerprint relative to the corresponding terminal historical baseline; performing cubic spline interpolation or linear interpolation on the abnormal residuals according to the acquisition time to obtain a continuous time control path; and using the abnormal terms in the trusted verification fingerprint as gating variables of the control path to adjust the state update amplitude of the neural controlled differential equation encoder.
[0012] Preferably, the neural controlled differential equation encoder obtains the risk trajectory state in the following manner: using the terminal continuous risk control path as the control signal and the terminal initial credible state as the initial hidden state, the hidden state is calculated over time using a vector field parameterized by a neural network; between two adjacent sampling times, the hidden state is updated according to the control path increment, the abnormal residual change rate, and the credible verification anomaly; the hidden state corresponding to the last time window is taken as the risk trajectory state.
[0013] Preferably, the hyperedge propagation strength in the trusted gating temporal risk hypergraph is determined based on the communication order, service dependency strength, spatial distance, anomalous residual similarity, and historical co-occurrence anomaly frequency of the nodes within the hyperedge; the trusted gating weight is determined based on the trusted attenuation coefficient of the nodes within the hyperedge, and the larger the trusted attenuation coefficient, the higher the risk propagation weight of the corresponding hyperedge.
[0014] Preferably, the trusted attenuation coefficient is calculated by weighting the number of device certificate failures, the number of startup chain hash inconsistencies, the number of firmware hash inconsistencies, the number of authentication failures, and the duration of abnormal residuals; when the trusted attenuation coefficient exceeds a preset threshold, the propagation strength of the communication session superedge and service call superedge containing the corresponding IoT terminal is increased.
[0015] Preferably, the entropy-regularized optimal transmission matching includes: using the risk trajectory state of each IoT terminal as the distribution to be matched, and using preset normal operation prototypes, reliable attenuation prototypes, lateral propagation prototypes, and environmentally induced anomaly prototypes as prototype distributions; constructing a transmission cost matrix based on the distance between the risk trajectory state and each risk prototype; solving the transmission matrix through entropy regularization terms; and determining the risk type and risk contribution of the IoT terminal based on the transmission cost corresponding to the lateral propagation prototype or reliable attenuation prototype in the transmission matrix.
[0016] Preferably, determining the risk source node includes: constructing a multidimensional anomaly event sequence from the moments when the abnormal residuals in each IoT terminal exceed a threshold; using a reliable attenuation coefficient to modulate the triggering kernel function of the Hawkes process to calculate the anomaly triggering intensity between different IoT terminals; identifying IoT terminals whose anomaly triggering intensity meets preset conditions as candidate risk source nodes; deleting the anomaly events corresponding to the candidate risk source nodes from the multidimensional anomaly event sequence and recalculating the anomaly occurrence probability of the affected nodes; and determining the candidate risk source node with the largest decrease in anomaly occurrence probability before and after counterfactual deletion as the risk source node.
[0017] Preferably, generating at least two levels of coordinated protection actions includes: constructing a node risk diffusion equation based on a trusted gating time-series risk hypergraph to predict the risk concentration of each IoT terminal in future time steps; inputting the current risk concentration, predicted risk concentration, node business importance, risk contribution, and executable protection actions into the protection policy network to output a candidate coordinated protection action sequence; eliminating candidate coordinated protection actions that do not meet business continuity constraints through a security shielding layer; and selecting a target coordinated protection action sequence from the remaining candidate coordinated protection action sequences.
[0018] Preferably, the security shielding layer sets prohibition conditions for different protection actions based on the importance of node services and service continuity constraints; when the target node is a critical service node and there is no backup node, terminal isolation, network disconnection, or firmware rollback operations are prohibited from being performed directly; when the target node is a non-critical service node and its risk concentration exceeds a preset high-risk threshold, terminal isolation, gateway blocking, or firmware rollback operations are allowed.
[0019] Compared with the prior art, the technical solution of the present invention has the following beneficial effects: This invention collects operational fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints, and constructs a continuous risk control path for the terminal by combining the time series of each fingerprint. This allows for the simultaneous characterization of terminal resource usage, process port changes, communication anomalies, declining trusted status, and inconsistencies between sensor states and control actions. Compared to detection methods that rely solely on single traffic thresholds, log alarms, or static rules, this invention can depict the continuous evolution of terminal risks from normal to abnormal states, improving the accuracy of identifying covert attacks, firmware tampering, abnormal control, and gradual risk accumulation.
[0020] This invention uses IoT terminals and edge gateways as nodes, and constructs communication session hyperedges, service call hyperedges, and spatial proximity hyperedges based on communication session links, service call links, and physical proximity areas, respectively, forming a trusted gating temporal risk hypergraph. Risk propagation analysis is then performed by combining hyperedge propagation strength and trusted gating weights. This approach can express one-to-many and many-to-many propagation relationships, such as one abnormal terminal simultaneously affecting multiple terminals, multiple terminals jointly participating in the same service link, and terminals in the same area experiencing linked anomalies, overcoming the problem that traditional pairwise node connection models cannot effectively depict the spread of group risks.
[0021] This invention performs entropy-regularized optimal transmission matching between risk trajectory states and normal operation prototypes, reliable attenuation prototypes, lateral propagation prototypes, and environment-induced anomaly prototypes. This allows for the differentiation of risk types and determination of risk contribution based on matching costs. Simultaneously, it generates tiered, coordinated protective actions for risk source nodes and affected nodes by incorporating business continuity constraints. Furthermore, it corrects the risk hypergraph and subsequent actions based on the risk residuals after action execution. This avoids excessive isolation or erroneous blocking of critical business terminals, suppressing risk spread while minimizing the impact on normal business operations. Attached Figure Description
[0022] Figure 1 This is a framework diagram of the intelligent risk perception and linkage protection system for IoT terminals according to the present invention; Figure 2 This is a flowchart of the terminal fingerprint collection and continuous risk control path construction of the present invention; Figure 3 This is a schematic diagram of the trusted gating timing risk hypergraph of the present invention; Figure 4 This is a flowchart of the closed-loop process for generating and executing the linkage protection action of the present invention. Detailed Implementation
[0023] Those skilled in the art will understand that, in order to make the above-mentioned objects, features, and beneficial effects of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Figure 1 This application illustrates an intelligent risk perception and linkage protection system for IoT terminals, comprising: The data acquisition unit collects operational fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints from each IoT terminal within a preset time window, and constructs a continuous risk control path for the terminal based on the time sequence of each fingerprint. In this embodiment, the data acquisition unit is deployed on the IoT security management platform, edge gateway, and / or locally on the IoT terminal. For IoT terminals with computing capabilities, the data acquisition unit can be deployed on the terminal side as a lightweight acquisition agent; for IoT terminals with weak computing capabilities or that do not support local agents, the data acquisition unit can be deployed on the edge gateway to obtain the status data of the corresponding terminal through network traffic bypass monitoring, management interface calls, log synchronization, or device management protocols.
[0024] The data acquisition unit collects operational fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints from each IoT terminal within a preset time window. The preset time window can be set according to the security level of the IoT scenario and the terminal type, for example, 30 seconds, 1 minute, 5 minutes, or 10 minutes. In high-security scenarios such as industrial control and access control, the preset time window can be set to 30 seconds or 1 minute; in low-frequency scenarios such as environmental monitoring and energy consumption data collection, the preset time window can be set to 5 minutes or 10 minutes. Within each preset time window, the data acquisition unit generates a set of fingerprint data for the same IoT terminal and forms a fingerprint time sequence for the corresponding terminal according to the acquisition time.
[0025] Specifically, the operational fingerprint is used to characterize changes in the local operating state of the IoT terminal, including at least three of the following: process startup changes, port opening changes, processor utilization changes, memory utilization changes, and peripheral device call changes. For example, for a camera terminal, the operational fingerprint may include whether the video acquisition process has restarted abnormally, whether an unknown process has been added, whether a non-preset port has been opened, whether the processor utilization has been consistently higher than the historical average, whether the memory utilization has suddenly increased, and whether abnormal peripheral device interfaces have been called. The data acquisition unit can represent the operational fingerprint as: Frun(t)=[p(t),q(t),c(t),m(t),u(t)]; where p(t) represents the process startup change characteristic, q(t) represents the port opening change characteristic, c(t) represents the processor utilization change characteristic, m(t) represents the memory utilization change characteristic, and u(t) represents the peripheral device call change characteristic.
[0026] The communication session fingerprint is used to characterize changes in the communication behavior of IoT terminals within the current time window, including at least three of the following: communication object, protocol port, packet length distribution, uplink / downlink traffic mutations, cross-network segment access counts, and authentication failure counts. For example, when an access control controller typically only communicates with the local edge gateway, but experiences a significant increase in access to external addresses, cross-network segment connections, abnormal port communication, or authentication failure counts within the current time window, the data acquisition unit writes these changes into the communication session fingerprint. The communication session fingerprint can be represented as: Fcom(t) = [a(t), r(t), l(t), v(t), s(t), f(t)]; where a(t) represents the communication object change characteristic, r(t) represents the protocol port change characteristic, l(t) represents the packet length distribution characteristic, v(t) represents the uplink / downlink traffic mutation characteristic, s(t) represents the cross-network segment access count characteristic, and f(t) represents the authentication failure count characteristic.
[0027] The trusted verification fingerprint is used to characterize the identity and firmware trusted status of the IoT terminal, including at least two of the following: device certificate status, startup chain hash verification result, firmware hash verification result, and security patch version status. The data acquisition unit can obtain the terminal certificate validity status, startup chain hash value, firmware hash value, and security patch version through the terminal trusted startup module, firmware management module, or device management platform. When the device certificate expires, the certificate fingerprint does not match, the startup chain hash is inconsistent, the firmware hash is inconsistent, or the security patch version is lower than a preset version, the corresponding anomaly is recorded as a trusted verification fingerprint. The trusted verification fingerprint can be represented as: Ftrust(t)=[ce(t),bh(t),fh(t),pa(t)]; where ce(t) represents the device certificate status, bh(t) represents the startup chain hash verification result, fh(t) represents the firmware hash verification result, and pa(t) represents the security patch version status.
[0028] The scene consistency fingerprint is used to characterize whether the actual environmental state collected by the IoT terminal is consistent with its control action and triggering conditions. This includes the matching relationship between the sensor-measured environmental state, the terminal control action, the control action triggering conditions, and the direction of environmental state change. For example, in a smart park scenario, if the light sensor does not detect a low-illuminance state when the lighting controller performs a light-on action, or if the light intensity does not change accordingly after the light-on action, the scene consistency is considered reduced. Similarly, if the temperature sensor does not display a high-temperature state when the air conditioner controller performs a cooling action, or if the temperature change direction is opposite to the expected direction after the cooling action, an abnormal scene consistency feature is generated. The scene consistency fingerprint can be represented as: Fscene(t)=[e(t),o(t),g(t),d(t)]; where e(t) represents the sensor-measured environmental state, o(t) represents the terminal control action, g(t) represents the control action triggering conditions, and d(t) represents the degree of matching between the direction of environmental state change and the expected direction of the control action.
[0029] After obtaining the four types of fingerprints mentioned above, the data acquisition unit normalizes each fingerprint to eliminate the impact of different dimensions on subsequent risk modeling. For continuous data, such as processor utilization, memory utilization, uplink and downlink traffic, and average packet length, maximum-minimum normalization or standardization can be used. For discrete data, such as whether a certificate is valid, whether a hash is consistent, and whether a port is abnormally open, 0 / 1 encoding or multi-level state encoding can be used. For categorical data, such as protocol type, communication object type, and terminal control action type, one-hot encoding or embedded vector encoding can be used.
[0030] Subsequently, the data acquisition unit calls upon the historical baselines of each IoT terminal to calculate the abnormal residuals of the fingerprint data within the current time window. The historical baseline can be composed of the historical fingerprint mean, variance, quantile range, or periodic behavior template of the corresponding terminal during its normal operation cycle. For a certain type of fingerprint F_i(t) of the i-th IoT terminal at time t, its abnormal residual can be expressed as: R_i(t)=|F_i(t)-B_i(t)| / σ_i; where B_i(t) represents the historical baseline of the terminal at the corresponding time position, and σ_i represents the historical fluctuation scale. For trusted verification fingerprints such as hash verification and certificate status, verification consistency can be recorded as 0, verification anomalies as 1, and the anomalies can be used as trusted gating variables to participate in the construction of subsequent continuous risk control paths.
[0031] Furthermore, the data acquisition unit concatenates the runtime fingerprint residual, communication session fingerprint residual, trusted verification anomaly item, and scenario consistency residual according to the acquisition time sequence to form a discrete risk state sequence: X_i={x_i(t1),x_i(t2),...,x_i(tn)}; where x_i(tk) represents the fused risk fingerprint vector corresponding to the i-th IoT terminal in the k-th time window. To enable the subsequent neural controlled differential equation encoder to handle continuous-time risk evolution, the data acquisition unit performs cubic spline interpolation or linear interpolation on the discrete risk state sequence to obtain the terminal continuous risk control path: X_i(t), t∈[t1,tn]; the terminal continuous risk control path is used to describe the risk evolution process of the i-th IoT terminal shifting from a normal state to an abnormal state within a continuous time range. Compared with static risk characteristics within a single time window, the continuous risk control path can retain the occurrence time, duration, direction of change, and rate of change of the abnormal residual. For example, for a certain camera terminal, if the number of authentication failures increases first, then abnormal external connections occur, and then firmware hash inconsistencies occur within multiple consecutive time windows, then the continuous risk control path can express the sequential evolution of the above risk states, rather than simply treating them as unrelated alarm events.
[0032] In one optional implementation, the data acquisition unit also uses anomalies in the trusted verification fingerprint as gating variables for the control path. For example, when a device certificate expires, the startup chain hash is inconsistent, or the firmware hash is inconsistent, the risk weight of the control path within the corresponding time period is increased, causing the subsequent neural controlled differential equation encoder to pay more attention to risk changes caused by trusted state mutations during state updates. Thus, the data acquisition unit not only completes multi-source data acquisition but also converts discrete, heterogeneous, and frequency-different terminal state data into a unified continuous risk control path for the terminal, providing an input basis for subsequent risk trajectory state generation, trusted gating temporal risk hypergraph construction, and risk propagation localization.
[0033] The risk trajectory state generation unit inputs the continuous risk control path of the terminal into a neural controlled differential equation encoder to obtain the risk trajectory state of each IoT terminal. In this embodiment, the risk trajectory state generation unit receives the continuous risk control path of the terminal output by the data acquisition unit and encodes the risk evolution process of each IoT terminal within a continuous time range using a neural controlled differential equation encoder to obtain the risk trajectory state corresponding to each IoT terminal. The risk trajectory state is used to characterize the comprehensive risk level, risk change direction, credible state decay trend, and abnormal evolution mode of the IoT terminal within the current analysis period.
[0034] Specifically, the risk trajectory state generation unit first obtains the terminal continuous risk control path corresponding to each IoT terminal. This terminal continuous risk control path is composed of runtime fingerprint residuals, communication session fingerprint residuals, trusted verification anomalies, and scene consistency residuals arranged in chronological order, used to describe the risk change process of the terminal within multiple consecutive time windows. For example, if a camera terminal experiences only minor changes in the communication object in a previous time period, followed by an increase in authentication failures, and then external address anomalies and firmware hash verification anomalies, then this terminal continuous risk control path can reflect the evolution of these anomalies from weak to strong, and from communication anomalies to trusted anomalies.
[0035] Before inputting into the neural controlled differential equation encoder, the risk trajectory state generation unit preprocesses the continuous risk control path of the terminal. Preprocessing includes dimensional alignment, missing value imputation, anomaly peak smoothing, and temporal sequence correction for different types of risk features. For fingerprint data collected at different frequencies, the risk trajectory state generation unit aligns them using a uniform time scale. For missing data within a short period, it can be supplemented by continuing the state of adjacent time windows, completing historical baselines, or replacing data with observation data from the edge gateway. For short-term spikes caused by network jitter or collection errors, smoothing can be performed by combining the changing trends of adjacent time windows; however, trusted verification anomalies are not smoothed or weakened to avoid reducing sensitivity to critical anomalies such as firmware tampering and certificate expiration.
[0036] After preprocessing, the risk trajectory state generation unit generates an initial hidden state based on the terminal's initial trusted state. This initial trusted state can be determined by the terminal device type, security level, number of historical risks, most recent certificate verification result, most recent firmware verification result, and security patch version status. For terminals that have been running stably for a long time, have valid certificates, consistent firmware hashes, and a low number of historical anomalies, their initial hidden state is set to a low-risk trusted state; for terminals with frequent historical alarms, outdated patch versions, or a history of abnormal external connections, their initial hidden state is set to a higher-sensitivity state. Therefore, even if different terminals exhibit similar abnormal residuals within the current time window, they can generate different risk trajectory states based on their historical trusted foundation.
[0037] The neural controlled differential equation encoder uses the terminal's continuous risk control path as the control signal and the terminal's initial trusted state as the initial hidden state, continuously updating the hidden state along the time sequence. Within each time period, the encoder determines whether the terminal's risk state is stabilizing, slightly deviating, rapidly deteriorating, or experiencing a trusted abrupt change based on the direction and magnitude of the control path's change. For example, when the communication session fingerprint residual gradually increases but the operational fingerprint and trusted verification fingerprint remain stable, the encoder identifies this change as a deviation in communication behavior; when the communication session fingerprint residual increases and trusted verification anomalies appear, the encoder identifies this evolution as a trusted decay risk caused by communication anomalies; when the scene consistency residual increases but both communication and trusted states remain stable, the encoder is more likely to identify this change as an environmentally induced anomaly or a risk of sensor control inconsistency.
[0038] In this embodiment, the neural controlled differential equation encoder includes an input mapping layer, a continuous state update layer, a trusted gating layer, and a trajectory convergence layer. The input mapping layer maps different types of fingerprint features in the continuous risk control path of the terminal to a unified latent space, enabling operational fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints to be compared and fused within the same risk representation space. The continuous state update layer continuously updates the terminal's latent state based on the changes in the continuous risk control path over time, ensuring that the encoding result includes not only the anomaly intensity at a given moment but also the order of anomaly occurrence, duration, and rate of change. The trusted gating layer adjusts the latent state update magnitude based on trusted verification anomalies. When device certificate failure, startup chain hash inconsistency, firmware hash inconsistency, or security patch version anomalies occur, the state update weight for the corresponding time period is increased, ensuring that trusted state mutations are significantly reflected in the risk trajectory state. The trajectory convergence layer aggregates the continuous latent states throughout the entire analysis period into a fixed-dimensional risk trajectory state.
[0039] In practice, the risk trajectory state generation unit reads the terminal's continuous risk control path in chronological order. For each continuous time period, the input mapping layer first extracts the risk characteristic changes within the current time period, and then the continuous state update layer combines the hidden state of the previous time period to generate the current hidden state. If the current time period only experiences brief traffic fluctuations, and subsequent time periods recover to near the historical baseline, the encoder reduces the impact of these brief fluctuations on the final risk trajectory state. If the abnormal residuals in the current time period continue to increase, accompanied by an increase in authentication failures, cross-network segment accesses, or trusted verification anomalies, the encoder increases the contribution of this continuous abnormal process to the final risk trajectory state. In this way, the risk trajectory state generation unit can distinguish between occasional disturbances and continuous risk evolution, reducing the probability of false alarms.
[0040] In a specific application scenario, the access control system in a smart park first experiences an increase in the number of authentication failures over multiple consecutive time windows, followed by cross-network segment access, and then inconsistencies between control actions and personnel access status. The risk trajectory state generation unit inputs this continuous risk control path into a neural controlled differential equation encoder. Based on the sequence of anomalies and their continuous changing trends, the encoder generates a risk trajectory state representing "accumulated authentication anomalies accompanied by business control anomalies." This risk trajectory state differs from simple communication traffic anomalies and simple environmental disturbance anomalies, providing more accurate input for the subsequent risk propagation and localization unit to determine the risk source node and affected nodes.
[0041] In another specific application scenario, an environmental sensor experiences a sudden change in its readings within a short period, but its communication partners, authentication status, firmware hash, and control actions remain normal, and adjacent sensors also exhibit similar environmental changes. The risk trajectory state generation unit encodes the terminal's risk trajectory state as a state biased towards environmentally induced anomalies based on the stable states of the scenario consistency fingerprint and trusted verification fingerprint, rather than directly identifying it as a network attack or terminal compromise. This avoids misjudgments caused by normal environmental changes.
[0042] The risk trajectory state output by the risk trajectory state generation unit can include a terminal comprehensive risk representation, a trust decay representation, a lateral propagation tendency representation, and an environment-induced anomaly representation. The comprehensive risk representation reflects the terminal's current overall risk level; the trust decay representation reflects the impact of certificate, boot chain, firmware, and patch state anomalies on the terminal's trustworthiness; the lateral propagation tendency representation reflects whether the terminal may propagate risk to other terminals; and the environment-induced anomaly representation reflects whether the anomaly may be caused by changes in the real environment or inconsistent control actions. These risk trajectory states are then input into the trust-gated timing risk hypergraph generation unit and the risk propagation localization unit to construct the risk hypergraph, perform optimal transmission matching, and determine the risk source node and affected nodes.
[0043] Through this embodiment, Figure 2 As shown, the risk trajectory state generation unit can convert discrete, heterogeneous, and frequency-varying IoT terminal fingerprint data into continuous-time risk trajectory states. It not only retains the intensity information of terminal anomalies but also preserves the order of occurrence, duration, trend of change, and impact of credible mutations. Compared to directly classifying or thresholding static features within a single time window, this embodiment can more accurately identify progressive attacks, covert lateral movement, credible state decay, and environment-induced anomalies, providing a reliable foundation for subsequent credible gating temporal risk hypergraph construction and coordinated protection decisions.
[0044] The Trusted Gated Temporal Risk Hypergraph Generation Unit uses IoT terminals and edge gateways as nodes to construct communication session hyperedges, service call hyperedges, and spatial proximity hyperedges based on the same communication session link, the same service call link, and the same physical proximity area, respectively, to generate a Trusted Gated Temporal Risk Hypergraph, and configures hyperedge propagation strength and trusted gated weights for each hyperedge. In this embodiment, as Figure 3 As shown, the trusted gating time-series risk supergraph generation unit is used to construct a time-series risk supergraph that expresses the cross-terminal propagation relationship of risks based on the communication relationships, service call relationships, physical deployment relationships, and trusted status of each node among IoT terminals and edge gateways. This trusted gating time-series risk supergraph differs from ordinary graph structures that only describe the connection relationship between two devices. It uses hyperedges to represent the association relationships between multiple nodes within the same communication session link, the same service call link, or the same physical proximity area, thereby characterizing one-to-many and many-to-many risk propagation patterns.
[0045] Specifically, the trusted gating timing risk hypergraph generation unit first determines the nodes in the graph. These nodes include various IoT terminals and edge gateways connected to the IoT system. IoT terminals may include cameras, access controllers, environmental sensors, smart lighting controllers, smart meters, industrial controllers, security alarms, temperature and humidity monitoring devices, etc.; edge gateways may include campus edge gateways, industrial gateways, building control gateways, protocol conversion gateways, or local security gateways. Each node is associated with a corresponding device identifier, device type, deployment area, affiliated service, access gateway, risk trajectory status, and trusted attenuation coefficient.
[0046] After determining the nodes, the trusted gating temporal risk hypergraph generation unit extracts the relationships between each node according to a preset time window. For each time window, communication session hyperedges, service call hyperedges, and spatial proximity hyperedges are constructed respectively. Since the terminal connection relationships, service call relationships, and risk status may change in different time windows, the generated risk hypergraph is temporal, that is, each time window corresponds to one risk hypergraph, and the hyperedges between adjacent time windows can be added, disappear, or have their weights updated.
[0047] A communication session hyperedge is used to represent multiple nodes that are associated within the same communication session link. In one specific implementation, the trusted gating timing risk hypergraph generation unit obtains communication session records from edge gateways, switches, routers, or security management platforms, and determines the communication link based on the session quintuple, session start time, session end time, protocol port, uplink / downlink traffic, and session direction. If an IoT terminal communicates with multiple terminals or external addresses via the same edge gateway within the same time window, or if multiple terminals participate in the same service session, these terminals and their corresponding edge gateways are grouped into the same communication session hyperedge. For example, if a camera terminal establishes video stream sessions with a storage server, a video analytics terminal, and a management platform simultaneously through an edge gateway, then the camera, edge gateway, storage server, video analytics terminal, and management platform can collectively form a communication session hyperedge. If the camera experiences abnormal external connections or abnormal packet length distribution, this communication session hyperedge can be used to express the potential spread of risk along the session link to multiple nodes.
[0048] A business call hyperedge is used to represent multiple nodes in the same business call chain. In one specific implementation, the trusted gate control timing risk hypergraph generation unit obtains business call relationships from the business orchestration system, device management platform, control policy table, or edge gateway call logs, and determines the set of devices in the same business chain based on the source of the control command, the execution terminal, the feedback terminal, and the business process identifier. For example, in the smart park access control business, personnel recognition cameras, access controllers, gate actuators, personnel access sensors, and local edge gateways jointly complete a passage control business; these nodes are then constructed as a business call hyperedge. If the camera recognition result is abnormal, the access controller experiences permission changes, or the gate action is inconsistent with the passage status, this business call hyperedge can reflect the potential cascading risks in the business chain.
[0049] Spatial proximity hyperedges are used to represent multiple nodes deployed in the same or adjacent physical areas. In one specific implementation, the trusted gating temporal risk hypergraph generation unit constructs spatial proximity hyperedges for multiple terminals that are physically within a preset range, located in the same functional area, or share the same environmental conditions, based on equipment installation location, floor, room, cabinet, production line, area number, or geographical coordinates. For example, temperature and humidity sensors, water immersion sensors, smoke sensors, cameras, and air conditioning controllers in the same equipment room can form a spatial proximity hyperedge; multiple industrial control terminals, sensors, and actuators on the same production line can also form a spatial proximity hyperedge. This type of hyperedge is used to express the combined impact of environmental disturbances, local network anomalies, or physical space linkage anomalies on multiple terminals.
[0050] After constructing the three types of hyperedges mentioned above, the Trusted Gated Temporal Risk Hypergraph Generation Unit configures the hyperedge propagation strength for each hyperedge. The hyperedge propagation strength characterizes the probability and impact of risk propagation along that hyperedge. For communication session hyperedges, the hyperedge propagation strength can be determined based on the communication sequence, frequency, duration, abrupt changes in uplink and downlink traffic, similarity in abnormal packet length distribution, and cross-segment access. If a low-trust terminal first experiences abnormal external connections, and subsequently other terminals in the same communication session hyperedge successively experience abnormal communication objects or an increase in authentication failures, then the propagation strength of that communication session hyperedge is increased.
[0051] For business call hyperedges, the propagation strength can be determined based on the business dependency strength, control command transmission direction, business execution order, scope of control action impact, and similarity of abnormal residuals. If the output of an upstream control node directly affects multiple downstream execution terminals, and the anomaly occurrence time of the downstream terminals lags behind the anomaly occurrence time of the upstream node, then the business call hyperedge has a high propagation strength. For example, if an access control terminal's recognition result is abnormal, and the access control controller and gate actuator subsequently exhibit abnormal control actions, then the system increases the propagation strength of this business call hyperedge.
[0052] For spatially adjacent hyperedges, the hyperedge propagation strength can be determined based on the spatial distance between nodes, the number of co-occurrences of anomalies in the same area, the consistency of environmental state changes, and the number of historical linkage anomalies. If multiple sensors in the same area simultaneously show abnormal readings, but the communication session and trusted verification are normal, the spatially adjacent hyperedge propagation strength can be increased to indicate that the anomaly is more likely to be induced by environmental factors. If only a few devices in the same area show trusted verification anomalies or abnormal external connections, while the environmental state of other devices is normal, the system can reduce the impact of spatially adjacent hyperedges on risk propagation judgment and avoid misjudging network attacks as environmental anomalies.
[0053] The trusted gating time-series risk hypergraph generation unit also configures a trusted gating weight for each hyperedge. The trusted gating weight is used to adjust the risk propagation sensitivity based on the trusted state of the nodes within the hyperedge. The trusted state can be determined by the device certificate status, startup chain hash verification result, firmware hash verification result, security patch version status, number of authentication failures, and duration of abnormal residuals. When there are nodes in the hyperedge with expired certificates, inconsistent firmware hashes, abnormal startup chain verification, or a continuously increasing number of authentication failures, the trusted gating weight of that hyperedge is increased, making the subsequent risk propagation localization unit pay more attention to the risk propagation relationships within that hyperedge. Conversely, when all nodes within the hyperedge are in a trusted state, and the abnormal residuals are only short-term fluctuations, the trusted gating weight of that hyperedge is decreased to reduce the interference of occasional communication fluctuations or environmental disturbances on risk propagation judgment.
[0054] In a specific application scenario, a camera terminal in a smart park experiences an increased number of abnormal external connections and authentication failures within multiple consecutive time windows, along with abnormal firmware hash verification results. This camera maintains communication sessions with a video storage server, video analytics terminal, and management platform via an edge gateway. Therefore, the system constructs a communication session hyperedge encompassing the camera, edge gateway, video storage server, video analytics terminal, and management platform. Due to significant camera reliability degradation and subsequent changes in communication partners within the same session link, the trusted gating temporal risk hypergraph generation unit increases the hyperedge propagation strength and trusted gating weight of this communication session hyperedge. This enables subsequent risk propagation localization units to prioritize determining whether lateral propagation risks exist on this session link.
[0055] In another specific application scenario, the access control service chain includes personnel recognition cameras, access controllers, turnstile actuators, personnel access sensors, and edge gateways. If the personnel recognition camera outputs an abnormal recognition result, the access controller experiences an abnormal permission change, and the turnstile actuator performs an opening action inconsistent with the triggering conditions, then the trusted access control timing risk hypergraph generation unit constructs and enhances the service call hyperedge. In this case, even if the devices are not in direct communication with each other, their risk associations within the same business process can be expressed through the service call hyperedge, thereby improving the ability to identify cascading anomalies in the service chain.
[0056] In another specific application scenario, temperature and humidity sensors, water immersion sensors, smoke sensors, and air conditioning controllers within the same data center area experience environmental state changes within the same time window. If the trusted verification fingerprints of these terminals are normal, the communication session fingerprints show no obvious anomalies, and the direction of environmental state changes is consistent, the trusted gating timing risk hypergraph generation unit increases the propagation strength of spatially adjacent hyperedges while maintaining the trusted gating weight at a low level, indicating that the anomaly is more likely to be an environment-induced anomaly than a network attack. If one of the terminals simultaneously experiences firmware hash anomalies or abnormal external connections, the system increases the trusted gating weight of that spatially adjacent hyperedge, indicating that there may be a linkage risk caused by the controlled terminal in that area.
[0057] Furthermore, the trusted gating temporal risk hypergraph generation unit can update the temporal risk hypergraph based on changes in hyperedges within adjacent time windows. If a communication session hyperedge persists across multiple consecutive time windows and the number of anomalous nodes within it gradually increases, its propagation strength continuously increases; conversely, if a hyperedge appears only within a single time window and the corresponding anomaly disappears in subsequent time windows, its propagation strength gradually decreases. Through this temporal update method, the system can distinguish between short-term, sporadic anomalies and continuously spreading risks.
[0058] Ultimately, the trusted gated temporal risk hypergraph output by the trusted gated temporal risk hypergraph generation unit includes a set of nodes, a set of communication session hyperedges, a set of service call hyperedges, a set of spatial proximity hyperedges, and for each hyperedge, its type, occurrence time window, propagation strength, trusted gated weight, and the risk trajectory status of associated nodes. This trusted gated temporal risk hypergraph is input into the risk propagation localization unit to further determine the risk source node, risk propagation hyperedge, and affected nodes by combining the entropy regularized optimal transmission matching results.
[0059] Through this embodiment, the trusted gating time-series risk supergraph generation unit can unify the communication relationships, service relationships, spatial relationships and trusted states in the Internet of Things system into the same risk propagation structure. It can not only depict the abnormal state of a single terminal, but also express the group risk propagation relationship formed between multiple terminals based on sessions, services and space, thereby providing a more accurate structured basis for subsequent risk source location and linkage protection decision-making.
[0060] The risk propagation and localization unit performs entropy-normalized optimal transmission matching between the risk trajectory state and preset normal operation prototype, trusted attenuation prototype, lateral propagation prototype and environmentally induced anomaly prototype, and determines the risk source node, risk propagation superedge and affected node based on the matching cost, superedge propagation strength and trusted gating weight. In this embodiment, the risk propagation and positioning unit is used to receive the risk trajectory status of each IoT terminal output by the risk trajectory status generation unit, and the trusted gating time-series risk hypergraph output by the trusted gating time-series risk hypergraph generation unit. The risk trajectory status of each terminal is matched with the preset risk prototype through the entropy regularization optimal transmission matching method, thereby determining the risk type and risk contribution of each terminal. Furthermore, the risk source node, risk propagation hyperedge and affected node are determined by combining the hyperedge propagation strength and trusted gating weight.
[0061] Specifically, the risk propagation and localization unit pre-sets multiple risk prototypes, including at least a normal operation prototype, a trust decay prototype, a lateral propagation prototype, and an environment-induced anomaly prototype. The normal operation prototype characterizes the risk trajectory characteristics of a terminal in a stable operating state, such as small fluctuations in the operating fingerprint, stable communication objects, normal trust verification, and control actions consistent with environmental changes. The trust decay prototype characterizes the risk trajectory characteristics of a decline in the terminal's identity or firmware trust status, such as device certificate failure, inconsistent startup chain hashes, inconsistent firmware hashes, long-term lag in security patch versions, or a continuous increase in the number of authentication failures. The lateral propagation prototype characterizes the trajectory characteristics of risk spreading along communication session links or service call links among multiple terminals, such as a terminal first experiencing abnormal external connections, followed by other terminals in the same session link or service link exhibiting similar anomalies. The environment-induced anomaly prototype characterizes the abnormal trajectory characteristics caused by changes in the real environment or disturbances in the scene state, such as multiple sensors in the same area simultaneously showing changes in readings, while the terminal's trust verification status and communication behavior remain normal.
[0062] Before matching, the risk propagation and location unit organizes the risk trajectory status of each IoT terminal. For multiple IoT terminals within the same preset time window, the risk propagation and location unit groups their risk trajectory statuses into a set of objects to be matched, and records the terminal identifier, its associated edge gateway, physical region, business link, associated communication session, and trust attenuation coefficient corresponding to each risk trajectory status. Through this organization, each risk trajectory status not only contains the terminal's own risk evolution information, but also establishes a correspondence with nodes and hyperedges in the trusted gating time-series risk hypergraph.
[0063] Subsequently, the risk propagation localization unit compares the risk trajectory status of each terminal with preset normal operation prototypes, trusted decay prototypes, lateral propagation prototypes, and environment-induced anomaly prototypes to obtain the matching cost for the risk trajectory status to transfer to each risk prototype. The lower the matching cost, the closer the terminal's risk trajectory status is to the corresponding risk prototype; the higher the matching cost, the greater the difference between the terminal's risk trajectory status and the corresponding risk prototype. For example, if a terminal exhibits firmware hash anomalies, device certificate status anomalies, and an increased number of authentication failures within multiple consecutive time windows, while the communication object does not change significantly, its matching cost with the trusted decay prototype is low; if a terminal first experiences abnormal external connections, and subsequently multiple terminals in the same communication session hyperedge exhibit similar communication residuals, its matching cost with the lateral propagation prototype is low.
[0064] In this embodiment, the risk propagation localization unit employs entropy regularization optimal transmission matching instead of simply selecting a single most similar prototype. Specifically, the risk propagation localization unit treats the risk trajectory states of multiple terminals as a whole as objects to be assigned, and multiple preset risk prototypes as matching targets. Through entropy regularization constraints, the matching results consider both the differences between the risk trajectory states and each risk prototype, while avoiding excessive concentration of matching results on a single prototype. Thus, even if a terminal has both communication anomalies and trust verification anomalies, the system can obtain a comprehensive matching result for it on the trust attenuation prototype and the lateral propagation prototype, rather than simply forcing it into a single category.
[0065] After matching using entropy regularization optimal transmission, the risk propagation localization unit obtains the matching results for each IoT terminal corresponding to each risk prototype. For terminals that are close to the normal operation prototype in the matching results, the risk propagation localization unit marks them as low-risk or normal; for terminals that are close to the trusted decay prototype, they are marked as trusted anomalous nodes; for terminals that are close to the lateral propagation prototype, they are marked as propagation-related nodes; and for terminals that are close to the environment-induced anomalous prototype, they are marked as environment-induced anomalous nodes. If a terminal is close to both the trusted decay prototype and the lateral propagation prototype, it indicates that the terminal has both a declining trusted state and may participate in the lateral spread of risk, and the system sets its risk priority higher than that of purely environment-induced anomalous nodes.
[0066] After determining the risk type of each terminal, the risk propagation localization unit further calculates the risk contribution of each terminal. The risk contribution represents the magnitude of a terminal's contribution to the current risk propagation process. In practice, the risk propagation localization unit comprehensively considers the terminal's matching degree with the lateral propagation prototype, its matching degree with the trusted attenuation prototype, the chronological order of anomaly occurrences, the duration of the anomaly residual, and the propagation strength of its hyperedge. If a terminal experiences a trusted verification anomaly or anomaly external connection early on, and multiple affected nodes subsequently appear in its communication session hyperedge or service call hyperedge, then that terminal has a high risk contribution. If a terminal only experiences a minor anomaly in a later stage, and its anomaly is weakly correlated with other nodes, then its risk contribution is low.
[0067] The risk propagation localization unit also determines risk propagation superedges by combining the trusted gating temporal risk supergraph. Specifically, the risk propagation localization unit traverses communication session superedges, service call superedges, and spatial proximity superedges, and determines whether a superedge belongs to a risk propagation superedge based on the risk type distribution of nodes within the superedge, matching cost, superedge propagation strength, and trusted gating weight. If a communication session superedge contains a high-risk contribution node, and multiple nodes within the superedge are close to the lateral propagation prototype, and the propagation strength and trusted gating weight of the superedge are both high, then the communication session superedge is identified as a risk propagation superedge. If an upstream node in a service call superedge first exhibits a trusted decay anomaly, and the downstream execution terminal subsequently exhibits a control action anomaly, then the service call superedge can also be identified as a risk propagation superedge. If multiple nodes within a spatial proximity superedge are mainly close to the environment-induced anomaly prototype, and the trusted gating weight is low, then the spatial proximity superedge is generally not identified as an attack propagation superedge, but is marked as an environment-related anomaly superedge.
[0068] After identifying the risk propagation superedge, the risk propagation localization unit further identifies the risk source node and affected nodes. Risk source nodes typically meet the following conditions: their anomaly occurrence time is earlier than other anomalous nodes within the same risk propagation superedge; their risk trajectory state has a high matching relationship with the trusted attenuation prototype or lateral propagation prototype; the propagation strength of their superedge is high; and the trusted gating weight of this node contributes significantly to the risk propagation of the superedge. Affected nodes typically exhibit anomaly occurrence times later than the risk source node, and are located within the same communication session superedge, service call superedge, or spatial proximity superedge as the risk source node; their risk trajectory state also has a certain matching relationship with the lateral propagation prototype or related anomaly prototypes.
[0069] In one specific implementation, the risk propagation localization unit can use the node with the earliest anomaly occurrence, the highest risk contribution, and located within a high-propagation-intensity hyperedge as the initial risk source node. Then, based on the order of anomaly occurrence and matching results within the same risk propagation hyperedge, subsequent nodes exhibiting anomalies are identified as affected nodes. If multiple candidate nodes meet the risk source condition, the impact of deleting each candidate node after counterfactual deletion is further compared. Specifically, the anomaly event corresponding to a candidate risk source node is deleted from the multidimensional anomaly event sequence, and the anomaly occurrence probability of other nodes within its hyperedge is reassessed. If deleting the candidate node results in the largest decrease in the anomaly occurrence probability of the affected nodes, then that candidate node is identified as the risk source node. This approach reduces the likelihood of misjudgments based solely on alarm timing.
[0070] For example, in a smart park video surveillance scenario, a camera experiences an increase in abnormal external connections and authentication failures in the first time window, an anomaly in its firmware hash verification in the second time window, and changes in the communication objects of the video analysis terminal and storage server located on the same communication session hyperedge in the third time window. The risk propagation localization unit matches the risk trajectory status of this camera with the trusted attenuation prototype and the lateral propagation prototype, finding that the matching cost is low; at the same time, the propagation strength and trusted gating weight of this communication session hyperedge are both high. Therefore, the risk propagation localization unit identifies this camera as the risk source node, the corresponding communication session hyperedge as the risk propagation hyperedge, and the video analysis terminal and storage server as affected nodes.
[0071] For example, in an access control scenario, personnel recognition cameras, access controllers, turnstile actuators, and personnel access sensors together constitute a service call hyperedge. If a personnel recognition camera first exhibits abnormal recognition results and increased communication residuals, followed by a permission change in the access controller and an opening action by the turnstile actuator inconsistent with the triggering conditions, the risk propagation and location unit determines this service call hyperedge as a risk propagation hyperedge based on the matching results of the service call sequence, the time of abnormal occurrence, the risk trajectory status of each node, and the lateral propagation prototype. If the personnel recognition camera also exhibits a trusted verification abnormality, it is identified as the risk source node; the access controller and turnstile actuator are identified as affected nodes.
[0072] For example, in a data center environment monitoring scenario, temperature and humidity sensors, water immersion sensors, smoke sensors, and air conditioning controllers are located near each other in the same spatial hyperedge. If multiple sensors show changes in environmental readings within the same time window, but the certificates, startup chain hashes, and firmware hashes of each terminal device are normal, and the communication objects and protocol ports have not changed abnormally, the risk propagation and localization unit will primarily match the risk trajectory status of the aforementioned terminals to the environmentally induced anomaly prototype. In this case, even if the anomaly co-occurrence rate of the spatially adjacent hyperedge is high, due to the low trusted gating weight, the risk propagation and localization unit will not classify it as a lateral attack propagation link, but rather mark it as an environmentally induced anomaly associated region. This avoids misjudging real environmental changes as network attacks.
[0073] In another complex scenario, if multiple terminals exhibit anomalies within the same time window, the risk propagation and localization unit does not directly treat all abnormal terminals as risk sources. Instead, it makes a comprehensive judgment based on the risk trajectory status of each terminal, the risk prototype matching result, the hyperedge propagation strength, the trust gating weight, and the order of anomaly occurrence. For example, if a terminal exhibits a high degree of anomaly but its anomaly occurs late and it is not located within a hyperedge with high propagation strength, it is more likely to be identified as an affected node. Conversely, if another terminal initially exhibits a low degree of anomaly but its trust status continuously decays, and multiple nodes within its hyperedge subsequently exhibit similar anomalies, then this terminal is more likely to be identified as a risk source node.
[0074] The risk propagation location unit outputs results including the risk source node identifier, risk propagation super-edge identifier, affected node identifier, risk type of each node, risk contribution of each node, and corresponding risk propagation path. These outputs are sent to the decision control unit, which generates different levels of coordinated protection actions based on the risk source node and affected nodes. For example, for the risk source node, priority is given to authentication revocation, session interruption, key update, or terminal isolation; for the affected nodes, priority is given to enhanced monitoring, access control contraction, communication rate limiting, or mandatory re-authentication.
[0075] In this embodiment, the risk propagation localization unit can combine the risk trajectory status of an individual terminal with the risk propagation structure of a group. It can not only identify whether a terminal is abnormal, but also further determine whether the abnormality is due to reliability decay, lateral propagation, or environmentally induced anomalies, and determine from which node the risk originates, along which hyperedge it propagates, and which nodes it affects. Compared to methods relying solely on threshold alarms, single-device classification, or ordinary graph propagation reasoning, this embodiment improves the accuracy of risk source localization and risk propagation link identification in complex IoT scenarios, providing a more reliable basis for subsequent coordinated protection decisions.
[0076] Decision control unit, such as Figure 4As shown, based on the risk source node, risk propagation hyperedge, affected node, and business continuity constraints, at least two levels of linked protection actions are generated for the risk source node and affected node, respectively. The trusted gating time-series risk hypergraph and subsequent linked protection actions are then modified based on the risk residual changes after the actions are executed.
[0077] In this embodiment, the decision control unit receives the risk source node, risk propagation superedge, affected nodes, node risk type, risk contribution, and risk propagation path output by the risk propagation location unit. It then generates at least two levels of coordinated protection actions for both the risk source node and the affected nodes, taking into account the business continuity constraints of each IoT terminal. These coordinated protection actions do not simply isolate or disconnect all abnormal terminals; instead, they are tiered and dynamically adjusted based on the risk propagation relationship, the importance of node services, the scope of the protection action's impact, and the change in risk residuals after the action's execution.
[0078] Specifically, the decision control unit first acquires the device attribute information corresponding to the risk source node and the affected node. This device attribute information includes device type, associated business, business importance, existence of a backup node, whether interruption is permitted, set of executable protective actions, record of the most recent protective action, and associated edge gateway. For critical business nodes, such as industrial controllers, access control main controllers, fire sensors, and medical monitoring terminals, business continuity constraints are high; for non-critical business nodes, such as ordinary cameras, environmental acquisition terminals, and temporary access sensors, business continuity constraints are relatively low. Based on the above information, the decision control unit determines the manageable scope for different nodes.
[0079] Before generating coordinated protection actions, the decision control unit constructs a node risk propagation prediction process based on the trusted gating time-series risk hypergraph. Specifically, the decision control unit reads the hyperedge type, hyperedge propagation strength, trusted gating weight, and risk contribution of each node within the hyperedge of the risk propagation hyperedge to predict which nodes the risk may propagate to in the future and the trend of risk concentration changes at each node. If a risk source node is located in a communication session hyperedge with high propagation strength and multiple affected nodes are already within that hyperedge, the system determines that the risk propagation speed is relatively fast; if the risk source node is only located in a spatially adjacent hyperedge and has a low trusted gating weight, the system determines that the risk is more likely to be an environmentally induced anomaly and reduces the strength of the protection action.
[0080] Subsequently, the decision control unit generates a first-level linkage protection action according to the risk type and risk contribution of the risk source node. The first-level linkage protection action is mainly used to suppress the risk source node from continuing to spread risks outward. For risk source nodes with obvious trusted attenuation risks, actions including authentication revocation, session interruption, key update, forced re-authentication, device certificate revocation or firmware integrity check are preferentially generated; for risk source nodes with abnormal external connection or horizontal propagation tendency, actions including access control contraction, abnormal session blocking, cross-network segment access prohibition, protocol port restriction or edge gateway blocking are preferentially generated; for risk source nodes with severe trusted verification abnormality and low service importance, actions including terminal isolation, network disconnection or firmware rollback can be directly generated.
[0081] For example, in the smart park video surveillance scenario, if a camera is determined to be a risk source node, and it has abnormal external connection, continuously increasing authentication failure times and inconsistent firmware hash, the decision control unit first generates a first-level protection action for the camera, including interrupting abnormal external connection sessions, revoking the current authentication token, updating the device key, and restricting it to only access the designated video management server through the edge gateway. If the camera is not a key service node and its risk contribution exceeds the high-risk threshold, a terminal isolation or firmware rollback action is further generated.
[0082] After generating the first-level linkage protection action, the decision control unit generates a second-level linkage protection action according to the risk status of the affected nodes. The second-level linkage protection action is mainly used to block the risk from continuing to spread along the risk propagation hyperedge and protect the nodes that have been affected but not yet completely out of control. For affected nodes located in the same communication session hyperedge as the risk source node, the decision control unit can generate actions including communication current limiting, abnormal session cleaning, access control contraction, forced re-authentication, and temporary blocking of communication requests from the risk source node; for affected nodes located in the same service call hyperedge as the risk source node, actions including control instruction recheck, service permission degradation, abnormal action rollback, manual trigger confirmation or standby node switching can be generated; for affected nodes in the same spatial adjacent hyperedge, if the risk is more likely to be environment-induced abnormality, actions including enhanced monitoring, increased sampling frequency, regional alarm push or multi-sensor consistency check can be generated, instead of directly performing network isolation.
[0083] For example, in the access control service scenario, if the person recognition camera is a risk source node, and the access controller and the gate actuator are affected nodes, the decision control unit generates authentication revocation and abnormal session blocking actions for the person recognition camera; meanwhile, it generates access permission contraction and control instruction recheck actions for the access controller, and generates abnormal action rollback and manual trigger confirmation actions for the gate actuator. This can not only suppress the further spread of risks, but also avoid interrupting the entire access control service by directly disconnecting the main access control device.
[0084] In this embodiment, the decision control unit is further provided with a security shielding layer. The security shielding layer is configured to eliminate actions that are not allowed to be executed according to service continuity constraints before the candidate linked protection actions are issued. Specifically, when the target node is a key service node and there is no standby node, the security shielding layer prohibits direct execution of terminal isolation, network disconnection or firmware rollback actions, and preferentially retains access control contraction, communication current limiting, forced re-authentication, session interruption or manual confirmation actions. When the target node is a non-critical service node and its risk concentration exceeds a preset high risk threshold, the security shielding layer allows execution of terminal isolation, gateway blocking or firmware rollback actions. When there is a standby node for the target node, the security shielding layer can first generate a standby node switching action, and then allow execution of isolation or rollback actions on the original node, thereby reducing the impact of the protection actions on service continuity.
[0085] The decision control unit may select a target linked protection action sequence from candidate linked protection action sequences through a protection policy network. Inputs of the protection policy network include current risk concentration, predicted risk concentration, node service importance, risk contribution, executable protection actions, risk propagation hyperedge types and trusted gating weights. The protection policy network outputs one or more candidate action sequences, each action sequence may include a first-level action for a risk source node and a second-level action for an affected node. After filtering the candidate action sequences through the security shielding layer, the decision control unit selects the action sequence with higher comprehensive benefit between risk reduction effect and service impact as the target linked protection action sequence.
[0086] In a specific implementation, the target linked protection action sequence is executed in the order of "suppressing the risk source first, then protecting the affected nodes, and finally monitoring adjacent hyperedges". First, perform authentication revocation, session interruption, key update or access control contraction on the risk source node; second, perform communication current limiting, forced re-authentication, control action review or standby node switching on the affected nodes; finally, perform enhanced monitoring, increased sampling frequency or alarm prompts on nodes in other hyperedges adjacent to the risk propagation hyperedge. If after executing the second-level action, the residual risk still does not drop to a preset range, the decision control unit can generate a third-level linked protection action, such as expanding the gateway blocking range, performing access control contraction on adjacent service call hyperedges, or temporarily isolating affected nodes with low service importance.
[0087] Regarding the distribution of protective actions, the decision control unit selects the corresponding execution target based on the action type. Actions such as authentication revocation, key update, forced re-authentication, and access control contraction can be distributed to the identity authentication server, access control device, or IoT management platform; actions such as abnormal session blocking, communication rate limiting, cross-network segment access prohibition, and protocol port restriction can be distributed to the edge gateway, firewall, or switching device; actions such as terminal isolation, device restart, firmware rollback, and patch update can be distributed to the terminal management agent or device management platform; and actions such as manual confirmation, alarm push, and handling suggestions can be sent to the security operation platform or management personnel terminal.
[0088] After the protective action is executed, the decision control unit continues to acquire the operational fingerprint, communication session fingerprint, trusted verification fingerprint, and scenario consistency fingerprint re-collected by the data acquisition unit, and calculates the risk residual change after the action execution. The risk residual change is used to evaluate whether the linkage protective action is effective. If the abnormal external connections of the risk source node disappear, the number of authentication failures decreases, trusted verification returns to normal, or the abnormal residual continues to decrease, it indicates that the first-level protective action is effective; if the communication anomaly of the affected node weakens, the control action returns to consistency, the risk concentration decreases, or the abnormal event no longer spreads to adjacent hyperedges, it indicates that the second-level protective action is effective.
[0089] Based on the changes in risk residuals after the actions are executed, the decision control unit corrects the trusted gating time-series risk hypergraph. When the risk residuals of the risk source node and affected nodes within a certain risk propagation hyperedge decrease significantly, the decision control unit lowers the hyperedge propagation strength and trusted gating weight of that risk propagation hyperedge, and reduces the level of subsequent protection actions, such as changing from terminal isolation to communication rate limiting, or from gateway blocking to enhanced monitoring. When the risk residuals do not decrease after the protection actions are executed, or the number of affected nodes increases, or new abnormal nodes appear in adjacent hyperedges, the decision control unit increases the propagation strength and trusted gating weight of the corresponding risk propagation hyperedge, and increases the level of subsequent protection actions, such as upgrading from access control contraction to gateway blocking, from communication rate limiting to terminal isolation, or expanding from single hyperedge handling to multi-hyperedge coordinated handling.
[0090] For example, in a video surveillance scenario, if the system interrupts the session and updates the key of a risky camera, but the camera continues to attempt to access external addresses, and the video analysis terminal continues to show abnormal communication object changes, the decision control unit determines that the original protection actions are insufficient and further generates terminal isolation and gateway blocking actions, while increasing the propagation strength of the corresponding communication session hyperedge. If, after terminal isolation, the risk residual of other nodes in the same communication session hyperedge decreases, the system reduces the trusted gating weight of that hyperedge and adjusts subsequent actions to enhanced monitoring.
[0091] For example, in a data center environment monitoring scenario, if multiple sensor anomalies are primarily matched as environment-induced anomalies, and their trusted verification status is normal, the decision control unit will not directly execute isolation or network disconnection. Instead, it will generate actions such as increasing the sampling frequency, pushing regional alarms, and performing multi-sensor consistency verification. If subsequent data collection indicates that the environmental state has returned to normal, and terminal communication and trusted status remain normal, the system will reduce the propagation intensity of spatially adjacent hyperedges and will not escalate to attack protection actions. This avoids over-protection due to changes in the actual environment.
[0092] In a preferred embodiment, the decision control unit also stores the risk propagation location results, protection action sequences, action execution results, and risk residual changes for each instance, forming a protection strategy experience record. When similar risk trajectory states and risk propagation exceedances occur subsequently, the decision control unit can refer to historical handling effects and prioritize the linked protection action sequences that previously reduced risk residuals quickly and had minimal business impact. For action sequences that failed to effectively reduce risk after execution, their subsequent selection priority is reduced. In this way, the system can gradually optimize the linked protection strategy during continuous operation.
[0093] In this embodiment, the decision control unit can generate differentiated protection actions based on the different roles of risk source nodes and affected nodes, avoid over-handling critical equipment according to business continuity constraints, and dynamically adjust the trusted gating timing risk hypergraph and subsequent protection actions based on changes in risk residuals after protection execution. Compared to fixed threshold triggering, single-point isolation, or manual handling, this embodiment can form a closed-loop linkage protection mechanism that includes risk location, hierarchical protection, execution feedback, graph structure correction, and policy upgrade or downgrade, thereby suppressing the spread of risks from IoT terminals while reducing the impact on normal business operations.
[0094] In some embodiments, the runtime fingerprint includes at least three of the following: process startup changes, port opening changes, processor utilization changes, memory utilization changes, and peripheral call changes; the communication session fingerprint includes at least three of the following: communication object, protocol port, packet length distribution, uplink and downlink traffic mutations, cross-network segment access counts, and authentication failure counts; the trusted verification fingerprint includes at least two of the following: device certificate status, startup chain hash verification result, firmware hash verification result, and security patch version status; and the scenario consistency fingerprint includes the matching relationship between the sensor measured environment status, terminal control actions, control action triggering conditions, and the direction of environment status change.
[0095] In some embodiments, constructing a continuous risk control path for a terminal includes: normalizing the runtime fingerprint, communication session fingerprint, trusted verification fingerprint, and scenario consistency fingerprint respectively; calculating the abnormal residuals of each fingerprint relative to the corresponding terminal historical baseline; performing cubic spline interpolation or linear interpolation on the abnormal residuals according to the acquisition time to obtain a continuous time control path; and using the abnormal terms in the trusted verification fingerprint as gating variables of the control path to adjust the state update amplitude of the neural controlled differential equation encoder.
[0096] In some embodiments, the neural controlled differential equation encoder obtains the risk trajectory state as follows: using the terminal continuous risk control path as the control signal and the terminal initial credible state as the initial hidden state, the hidden state is calculated over time using a vector field parameterized by a neural network; between two adjacent sampling times, the hidden state is updated based on the control path increment, the abnormal residual change rate, and the credible verification anomaly term; and the hidden state corresponding to the last time window is taken as the risk trajectory state.
[0097] In some embodiments, the hyperedge propagation strength in the trusted gating temporal risk hypergraph is determined based on the communication order of nodes within the hyperedge, the intensity of service dependency, spatial distance, similarity of abnormal residuals, and the number of historical co-occurring anomalies; the trusted gating weight is determined based on the trusted attenuation coefficient of nodes within the hyperedge, and the larger the trusted attenuation coefficient, the higher the risk propagation weight of the corresponding hyperedge.
[0098] In some embodiments, the trusted attenuation coefficient is calculated by weighting the number of device certificate failures, the number of startup chain hash inconsistencies, the number of firmware hash inconsistencies, the number of authentication failures, and the duration of abnormal residuals. When the trusted attenuation coefficient exceeds a preset threshold, the propagation strength of the communication session superedge and service call superedge containing the corresponding IoT terminal is increased.
[0099] In some embodiments, the entropy-regularized optimal transmission matching includes: using the risk trajectory state of each IoT terminal as the distribution to be matched, and using preset normal operation prototypes, reliable attenuation prototypes, lateral propagation prototypes, and environmentally induced anomaly prototypes as prototype distributions; constructing a transmission cost matrix based on the distance between the risk trajectory state and each risk prototype; solving the transmission matrix through entropy regularization terms; and determining the risk type and risk contribution of the IoT terminal based on the transmission cost corresponding to the lateral propagation prototype or reliable attenuation prototype in the transmission matrix.
[0100] In this embodiment, entropy-regularized optimal transmission matching is used to assign the risk trajectory states of multiple IoT terminals to multiple preset risk prototypes. Specifically, the risk propagation localization unit does not directly classify terminals as normal or abnormal based on a single threshold. Instead, it uses the risk trajectory states of each IoT terminal within the same time window as the objects to be matched, and uses the normal operation prototype, the reliable attenuation prototype, the lateral propagation prototype, and the environment-induced anomaly prototype as the matching targets. By calculating the degree of difference between the risk trajectory state and each risk prototype, the corresponding matching cost is obtained. The lower the matching cost, the closer the risk trajectory state of the terminal is to the corresponding risk prototype. By solving the transmission matrix through entropy regularization, the matching results can be flexibly allocated among multiple risk prototypes, rather than forcibly classifying the terminal into a single category. Thus, for terminals that simultaneously have communication anomalies and reliable verification anomalies, the system can identify that they have both reliable attenuation characteristics and lateral propagation tendencies, thereby improving the accuracy of complex risk state identification.
[0101] Furthermore, the elements in the transmission matrix represent the degree of matching between the risk trajectory state of a certain IoT terminal and a certain risk prototype. The risk propagation and localization unit determines the terminal risk type and risk contribution based on the matching results of the corresponding normal operation prototype, trusted decay prototype, lateral propagation prototype, and environment-induced anomaly prototype in the transmission matrix. For example, when a terminal has the lowest matching cost with the normal operation prototype and a low degree of matching with other anomaly prototypes, it is identified as a normal or low-risk terminal; when a terminal has a low matching cost with the trusted decay prototype, it indicates that the terminal may have issues such as certificate expiration, startup chain anomalies, firmware hash inconsistencies, or delayed security patches, indicating a decline in trusted status; when a terminal has a low matching cost with the lateral propagation prototype, it indicates that the terminal may participate in cross-terminal risk propagation; when a terminal has a low matching cost with the environment-induced anomaly prototype, it indicates that the terminal anomaly is more likely caused by changes in the real environment or inconsistencies between control actions and the environmental state. Through this method, the system can distinguish between network attack-type anomalies, trusted decay-type anomalies, and environment-induced anomalies, avoiding the simplistic treatment of all anomaly terminals as the same risk type.
[0102] In this embodiment, the Hawkes process is used to characterize the impact of an abnormal event of one IoT terminal on the triggering of subsequent abnormal events of other IoT terminals. Specifically, the risk propagation location unit records the moment when the abnormal residual in each IoT terminal exceeds a threshold as an abnormal event. Abnormal events may include abnormal external connections, a sudden increase in the number of authentication failures, inconsistent firmware hashes, abnormally open ports, abnormal control actions, or abnormal scene consistency. For multiple terminals within the same risk propagation hyperedge, if the first terminal experiences an abnormal event first, and the second terminal experiences a similar abnormal event in a subsequent time window, then the abnormal event of the first terminal is considered to have a triggering effect on the abnormal event of the second terminal. The Hawkes process is used to measure this temporal triggering relationship of an anomaly occurring first and subsequently inducing another, thereby determining whether the anomaly propagates along the communication session hyperedge, service call hyperedge, or spatial proximity hyperedge.
[0103] Furthermore, the risk propagation localization unit modulates the trigger kernel function of the Hawkes process using a trust decay coefficient. A higher trust decay coefficient indicates that the corresponding terminal has issues such as certificate expiration, abnormal startup chain hash, abnormal firmware hash, a continuous increase in authentication failures, or a longer duration of abnormal residuals, making the resulting abnormal events more likely to trigger subsequent risk propagation. Therefore, when a terminal with a higher trust decay coefficient experiences an abnormal event first, the system increases the trigger strength of that terminal for other terminals within the same hyperedge; when the trust decay coefficient is low and the abnormality is only a short-term fluctuation, the system reduces its trigger strength. Thus, risk source localization no longer relies solely on the order of alarm times, but comprehensively considers the type of abnormal event, its occurrence order, the degree of trust decay, and the hyperedge propagation relationship, improving the accuracy of distinguishing between risk source nodes and affected nodes.
[0104] In a specific scenario, a camera terminal first experiences an increase in abnormal external connections and authentication failures, followed by an anomaly in its firmware hash verification. Within a subsequent time window, video analytics terminals and storage servers located on the same communication session hyperedge as the camera successively experience changes in their communication objects. The risk propagation localization unit determines that the camera is simultaneously close to both the trusted attenuation prototype and the lateral propagation prototype through entropy regularized optimal transmission matching. Furthermore, it calculates, using a Hawkes process modulated with the trusted attenuation coefficient, that the camera has a high triggering strength for subsequent abnormal events. Therefore, the system identifies the camera as the risk source node, the corresponding communication session hyperedge as the risk propagation hyperedge, and the video analytics terminal and storage server as affected nodes. This approach avoids misjudgments based solely on the number of anomalies or the intensity of a single alarm.
[0105] In some embodiments, determining the risk source node includes: constructing a multidimensional anomaly event sequence from the moments when the abnormal residuals in each IoT terminal exceed a threshold; calculating the anomaly triggering intensity among different IoT terminals by modulating the triggering kernel function of the Hawkes process using a reliable attenuation coefficient; identifying IoT terminals whose anomaly triggering intensity meets a preset condition as candidate risk source nodes; deleting the anomaly events corresponding to the candidate risk source nodes from the multidimensional anomaly event sequence and recalculating the anomaly occurrence probability of the affected nodes; and determining the candidate risk source node with the largest decrease in anomaly occurrence probability before and after counterfactual deletion as the risk source node.
[0106] In some embodiments, generating at least two levels of coordinated protection actions includes: constructing a node risk diffusion equation based on a trusted gating temporal risk hypergraph to predict the risk concentration of each IoT terminal in future time steps; inputting the current risk concentration, predicted risk concentration, node business importance, risk contribution, and executable protection actions into the protection policy network to output a candidate coordinated protection action sequence; eliminating candidate coordinated protection actions that do not meet business continuity constraints through a security shielding layer; and selecting a target coordinated protection action sequence from the remaining candidate coordinated protection action sequences.
[0107] In some embodiments, the security shielding layer sets prohibition conditions for different protection actions based on the importance of node services and service continuity constraints; when the target node is a critical service node and there is no backup node, terminal isolation, network disconnection, or firmware rollback operations are prohibited from being performed directly; when the target node is a non-critical service node and its risk concentration exceeds a preset high-risk threshold, terminal isolation, gateway blocking, or firmware rollback operations are allowed.
[0108] The vector field network in the neural controlled differential equation encoder employs a trusted propagation adaptive activation function. This function determines risk-sensitive adjustment coefficients based on anomaly residual attention weights, trusted decay attention weights, hyperedge propagation attention weights, and scene inconsistency attention weights. These risk-sensitive adjustment coefficients are used to adjust the slope of the activation function during the hidden state update process. Specifically, the anomaly residual attention weights are determined based on the anomalies in the runtime fingerprint and communication session fingerprint relative to the historical baseline; the trusted decay attention weights are determined based on the anomalies in the trusted verification fingerprint; the hyperedge propagation attention weights are determined based on the hyperedge propagation strength and trusted gating weights; and the scene inconsistency attention weights are determined based on the scene consistency fingerprint.
[0109] In a preferred embodiment, the vector field network in the neural controlled differential equation encoder employs a trusted propagation adaptive activation function. Unlike a fixed activation function, the trusted propagation adaptive activation function dynamically adjusts the activation slope based on the abnormal residual state, trusted decay state, risk propagation structure state, and scene consistency state of the IoT terminal within the current time window, making the neural controlled differential equation encoder more sensitive to trusted anomalies and propagation anomalies when the risk state is updated. Specifically, the trusted propagation adaptive activation function is expressed as follows:
[0110] Where x represents the input value during the current hidden state update in the neural controlled differential equation encoder. Indicates activation of output. This represents the risk sensitivity adjustment coefficient of the i-th IoT terminal at time t. The risk sensitivity adjustment coefficient is determined by weighting the abnormal residual attention weight, the reliable decay attention weight, the super-edge propagation attention weight, and the scene inconsistency attention weight.
[0111] In some embodiments,
[0112] Indicates the attention weights of abnormal residuals; , represents the credible decay attention weight; , indicates the attention weight for superedge propagation; Indicates attention weights that are inconsistent across scenarios. The corresponding weighting coefficients are as follows: The anomaly residual attention weight is determined based on the anomaly residuals of the running fingerprint and communication session fingerprint relative to the terminal's historical baseline, used to characterize the degree of anomalies in terminal processes, ports, resource usage, communication objects, protocol ports, traffic mutations, and authentication failure states; the trust decay attention weight is determined based on the device certificate status, startup chain hash verification result, firmware hash verification result, and security patch version status, used to characterize the degree of decline in terminal identity trustworthiness and firmware trustworthiness; the hyperedge propagation attention weight is determined based on the hyperedge propagation strength and trust gating weight of the hyperedge of the communication session where the terminal is located, the hyperedge of the service call, or the hyperedge of spatial proximity, used to characterize the likelihood of the terminal participating in risk propagation; and the scenario inconsistency attention weight is determined based on the matching relationship between the sensor's measured environmental state, terminal control actions, control action triggering conditions, and the direction of environmental state change, used to characterize the degree of inconsistency between the terminal's control behavior and the actual scenario.
[0113] When an IoT terminal experiences only short-term traffic fluctuations or occasional resource usage changes, and its trusted verification status is normal and its propagation strength in the hyperedge is low, the risk sensitivity adjustment coefficient is small, and the slope of the trusted propagation adaptive activation function decreases, thereby reducing the impact of short-term disturbances on the risk trajectory status. When an IoT terminal simultaneously experiences abnormal residuals that continuously increase, device certificate failure, firmware hash inconsistency, or is located in a hyperedge of a high propagation strength communication session, the risk sensitivity adjustment coefficient increases, and the slope of the trusted propagation adaptive activation function increases, thereby enhancing the response of the neural controlled differential equation encoder to trusted decay risk and lateral propagation risk.
[0114] For example, if a camera terminal first experiences an increase in authentication failures within a continuous time window, followed by abnormal external connections, and the video analytics terminal in its communication session's hyperedge also experiences a change in communication targets, then the camera's abnormal residual attention weight, trusted decay attention weight, and hyperedge propagation attention weight all increase. In this case, the trusted propagation adaptive activation function increases the state update amplitude of the neural controlled differential equation encoder, making the camera's risk trajectory state more clearly biased towards the trusted decay prototype and the lateral propagation prototype. Conversely, if multiple environmental sensors in the same area experience reading fluctuations only due to changes in the real environment, and the device certificate, startup chain hash, firmware hash, and communication session are all normal, then the trusted propagation adaptive activation function reduces the response strength to such fluctuations, avoiding misjudging environmentally induced anomalies as attack propagation risks.
[0115] Through the aforementioned trusted propagation adaptive activation function, the neural controlled differential equation encoder can incorporate terminal anomalies, trusted state changes, hyper-edge propagation relationships, and scene consistency states into the hidden state update process, thereby improving the ability of risk trajectory states to distinguish between progressive attacks, trusted decay, lateral propagation, and scene anomalies.
[0116] This embodiment provides an intelligent risk perception and linkage protection system for IoT terminals, which includes, in terms of hardware, an IoT terminal, a terminal trusted acquisition component, an edge gateway, a network switching device, an access control device, an edge computing server, a risk analysis server, an authentication management server, a firmware management server, a data storage server, a linkage control server, and an operation and maintenance management terminal.
[0117] The IoT terminals include one or more of the following: cameras, access controllers, gate actuators, environmental sensors, smart meters, industrial controllers, lighting controllers, air conditioning controllers, smoke sensors, and water immersion sensors. Each IoT terminal generates operational status, communication behavior, control actions, and environmental perception data. The IoT terminals connect to the edge gateway or network switching equipment via Ethernet, RS485, CAN, Wi-Fi, ZigBee, LoRa, NB-IoT, or 5G communication methods.
[0118] The trusted terminal acquisition component is located locally on the IoT terminal or within an edge gateway connected to the IoT terminal. The trusted terminal acquisition component includes at least one of a lightweight acquisition agent, a trusted boot module, a security chip, a firmware hash verification module, and a device certificate storage module. The trusted terminal acquisition component is connected to the IoT terminal's processor, memory, communication interface, and peripheral interfaces, and is used to acquire data on process startup changes, port opening changes, resource usage changes, peripheral call changes, device certificate status, boot chain hash verification results, and firmware hash verification results.
[0119] The edge gateway connects to multiple IoT terminals, network switching devices, and edge computing servers. It aggregates data uploaded by each IoT terminal, records terminal communication session information, and performs preliminary analysis of terminal communication traffic. For IoT terminals lacking local data collection capabilities, the edge gateway collects their communication session fingerprints and operational status data through bypass monitoring, protocol parsing, log synchronization, or management interface calls. The edge gateway also receives communication rate limiting, abnormal session blocking, protocol port restriction, and terminal isolation commands from the linkage control server.
[0120] The network switching device connects the IoT terminal, edge gateway, and access control device to enable terminal access, LAN forwarding, and data offloading. The network switching device can be configured with mirroring ports to mirror terminal communication traffic to the edge gateway or edge computing server, thereby generating communication session fingerprints. The access control device connects the edge gateway to the upper-layer management network and includes firewalls, zero-trust gateways, intrusion prevention devices, or access control gateways. It is used to perform access control contraction, cross-segment access blocking, abnormal session interruption, and security policy distribution.
[0121] The edge computing server is connected to the edge gateway, network switching equipment, and risk analysis server. The edge computing server deploys data acquisition units and risk trajectory status generation units, receives operational fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints uploaded by the edge gateway, and constructs continuous risk control paths for terminals based on the time series of each fingerprint. The edge computing server also runs a neural controlled differential equation encoder to generate risk trajectory statuses for each IoT terminal. For scenarios with large data volumes or high real-time requirements, risk trajectory statuses can be generated locally on the edge computing server to reduce uplink transmission pressure.
[0122] The risk analysis server is connected to the edge computing server, data storage server, and linkage control server. The risk analysis server is used to deploy a trusted gated temporal risk hypergraph generation unit and a risk propagation location unit. The risk analysis server receives the risk trajectory status of each IoT terminal and, in conjunction with the communication session links provided by the edge gateway, the business call links provided by the business system, and the physical deployment locations provided by the device ledger, constructs communication session hyperedges, business call hyperedges, and spatial proximity hyperedges to generate a trusted gated temporal risk hypergraph. The risk analysis server is also used to perform entropy-regularized optimal transmission matching between the risk trajectory status and normal operation prototypes, trusted attenuation prototypes, lateral propagation prototypes, and environment-induced anomaly prototypes to determine the risk source node, risk propagation hyperedge, and affected nodes.
[0123] The authentication management server is connected to IoT terminals, edge gateways, access control devices, and a linkage control server. The authentication management server manages device certificates, identity tokens, keys, and access permissions. When the linkage control server generates actions such as authentication revocation, key update, forced reauthentication, or access permission reduction, the authentication management server executes the corresponding identity authentication adjustment operation and feeds back the execution results to the linkage control server and the risk analysis server.
[0124] The firmware management server is connected to the IoT terminal, edge gateway, and linkage control server. The firmware management server stores the standard firmware version, firmware hash value, security patch files, and rollback image of the IoT terminal. When the linkage control server generates firmware integrity verification, patch update, or firmware rollback operations, the firmware management server sends the corresponding firmware package, patch package, or rollback image to the target IoT terminal or edge gateway and receives the execution results.
[0125] The data storage server is connected to the edge computing server, risk analysis server, and linkage control server. The data storage server stores historical baselines, fingerprint time series, anomaly residuals, risk trajectory states, trusted gating time-series risk hypergraphs, risk prototypes, linkage protection action records, and risk residual changes after action execution for IoT terminals. The data storage server may include a relational database, a time-series database, and a graph database. The time-series database stores terminal fingerprint time series, and the graph database stores the trusted gating time-series risk hypergraph and its hyperedge relationships.
[0126] The linkage control server is connected to the risk analysis server, authentication management server, firmware management server, edge gateway, access control devices, and operation and maintenance management terminal. The linkage control server is used to deploy decision control units and generate at least two levels of linkage protection actions based on risk source nodes, risk propagation superedges, affected nodes, and business continuity constraints. For risk source nodes, the linkage control server can issue commands for authentication revocation, session interruption, key update, access control contraction, terminal isolation, or firmware rollback. For affected nodes, the linkage control server can issue commands for communication rate limiting, forced re-authentication, control action verification, backup node switching, or enhanced monitoring. The linkage control server also feeds back correction information for superedge propagation strength and trusted gating weights to the risk analysis server based on changes in risk residuals after action execution.
[0127] The operation and maintenance management terminal is connected to the linkage control server, risk analysis server, and data storage server. The operation and maintenance management terminal can be a security operation workstation, management computer, mobile terminal, or large visualization screen, used to display risk source nodes, risk propagation paths, affected nodes, linkage protection actions, action execution status, and risk residual changes. For high-impact protection actions requiring manual confirmation, the operation and maintenance management terminal receives confirmation requests from the linkage control server and feeds back the manual confirmation results to the linkage control server.
[0128] The specific connection relationships between the various hardware components are as follows: multiple IoT terminals connect to the edge gateway or network switching device via wired or wireless means; the edge gateway connects to the access control device and the edge computing server via the network switching device; the edge computing server connects to the risk analysis server via a dedicated management network or secure communication channel; the risk analysis server connects to the data storage server and the linkage control server respectively; the linkage control server connects to the authentication management server, firmware management server, access control device, edge gateway, and operation and maintenance management terminal respectively; the authentication management server and firmware management server connect to the IoT terminals via the edge gateway or device management channel.
[0129] In the data flow direction, IoT terminals and edge gateways upload the collected operation fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints to the edge computing server; the edge computing server generates a risk trajectory status and sends it to the risk analysis server; the risk analysis server generates a risk propagation location result and sends it to the linkage control server; the linkage control server distributes linkage protection actions to the authentication management server, firmware management server, access control device, edge gateway, or target IoT terminal respectively; the action execution results and new terminal status data are then transmitted back to the edge computing server, risk analysis server, and data storage server, thus forming a closed-loop hardware connection structure of risk perception, propagation location, linkage protection, and feedback correction.
[0130] Compared with the prior art, the technical solution of the present invention has the following beneficial effects: (1) This invention collects operational fingerprints, communication session fingerprints, trusted verification fingerprints, and scenario consistency fingerprints, and constructs a continuous risk control path for the terminal by combining the time series of each fingerprint. This allows for the simultaneous characterization of terminal resource usage, process port changes, communication anomalies, decline in trusted status, and inconsistencies between sensor status and control actions. Compared to detection methods that rely solely on single traffic thresholds, log alarms, or static rules, this invention can depict the continuous process of terminal risk evolution from a normal state to an abnormal state, improving the accuracy of identifying covert attacks, firmware tampering, abnormal control, and gradual risk accumulation.
[0131] (2) This invention uses IoT terminals and edge gateways as nodes, and constructs communication session hyperedges, service call hyperedges, and spatial proximity hyperedges based on communication session links, service call links, and physical proximity areas, respectively, to form a trusted gating temporal risk hypergraph. Risk propagation analysis is then performed by combining the hyperedge propagation strength and trusted gating weights. This method can express one-to-many and many-to-many propagation relationships, such as one abnormal terminal affecting multiple terminals simultaneously, multiple terminals participating in the same service link, and terminals in the same area experiencing linked anomalies. This overcomes the problem that traditional pairwise node connection models cannot effectively depict the spread of group risks.
[0132] (3) This invention performs entropy-regularized optimal transmission matching between the risk trajectory state and the normal operation prototype, reliable attenuation prototype, lateral propagation prototype, and environment-induced anomaly prototype. It can distinguish the risk type and determine the risk contribution based on the matching cost. At the same time, it generates hierarchical linkage protection actions for risk source nodes and affected nodes in combination with business continuity constraints, and corrects the risk hypergraph and subsequent actions based on the risk residual after the action is executed. This can avoid excessive isolation or false blocking of critical business terminals, and reduce the impact on normal business operations while suppressing the spread of risks.
[0133] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products, and therefore this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects.
[0134] While the present invention has been disclosed above, it is not limited thereto. Any person skilled in the art can make various modifications and alterations without departing from the spirit and scope of the invention; therefore, the scope of protection of the present invention should be determined by the scope defined in the claims.
Claims
1. A smart risk perception and linkage protection system for Internet of Things (IoT) terminals, characterized in that, include: The data acquisition unit collects the operation fingerprint, communication session fingerprint, trusted verification fingerprint and scenario consistency fingerprint of each IoT terminal in a preset time window, and constructs a continuous risk control path for the terminal based on the time sequence of each fingerprint. The risk trajectory state generation unit inputs the continuous risk control path of the terminal into the neural controlled differential equation encoder to obtain the risk trajectory state of each Internet of Things terminal. The Trusted Gated Temporal Risk Hypergraph Generation Unit uses IoT terminals and edge gateways as nodes to construct communication session hyperedges, service call hyperedges, and spatial proximity hyperedges based on the same communication session link, the same service call link, and the same physical proximity area, respectively, to generate a Trusted Gated Temporal Risk Hypergraph, and configures hyperedge propagation strength and trusted gated weights for each hyperedge. The risk propagation and localization unit performs entropy-normalized optimal transmission matching between the risk trajectory state and preset normal operation prototype, trusted attenuation prototype, lateral propagation prototype and environmentally induced anomaly prototype, and determines the risk source node, risk propagation superedge and affected node based on the matching cost, superedge propagation strength and trusted gating weight. The decision control unit generates at least two levels of linked protection actions for the risk source node and the affected node, respectively, based on the risk source node, risk propagation hyperedge, affected node, and business continuity constraints. It also corrects the trusted gating time-series risk hypergraph and subsequent linked protection actions based on the risk residual changes after the actions are executed.
2. The intelligent risk perception and linkage protection system for IoT terminals according to claim 1, characterized in that, The operational fingerprint includes at least three of the following: process startup changes, port opening changes, processor utilization changes, memory utilization changes, and peripheral call changes; the communication session fingerprint includes at least three of the following: communication object, protocol port, packet length distribution, uplink and downlink traffic mutations, cross-network segment access counts, and authentication failure counts; the trusted verification fingerprint includes at least two of the following: device certificate status, startup chain hash verification result, firmware hash verification result, and security patch version status; the scenario consistency fingerprint includes the matching relationship between the sensor measured environment status, terminal control actions, control action triggering conditions, and the direction of environment status change.
3. The intelligent risk perception and linkage protection system for IoT terminals according to claim 2, characterized in that, The construction of a continuous risk control path for the terminal includes: normalizing the operation fingerprint, communication session fingerprint, trusted verification fingerprint, and scenario consistency fingerprint respectively; calculating the abnormal residuals of each fingerprint relative to the corresponding terminal historical baseline; performing cubic spline interpolation or linear interpolation on the abnormal residuals according to the acquisition time to obtain a continuous time control path; and using the abnormal terms in the trusted verification fingerprint as the gating variables of the control path to adjust the state update amplitude of the neural controlled differential equation encoder.
4. The intelligent risk perception and linkage protection system for IoT terminals according to claim 3, characterized in that, The neural controlled differential equation encoder obtains the risk trajectory state as follows: using the terminal continuous risk control path as the control signal and the terminal initial credible state as the initial hidden state, the hidden state is calculated over time using a vector field parameterized by the neural network; between two adjacent sampling times, the hidden state is updated based on the control path increment, the abnormal residual change rate, and the credible verification anomaly; the hidden state corresponding to the last time window is taken as the risk trajectory state.
5. The intelligent risk perception and linkage protection system for IoT terminals according to claim 3, characterized in that, The propagation strength of the hyperedge in the trusted gating temporal risk hypergraph is determined based on the communication order of nodes within the hyperedge, the intensity of service dependency, spatial distance, similarity of abnormal residuals, and the number of historical co-occurrence anomalies. The trusted gating weight is determined based on the trusted attenuation coefficient of nodes within the hyperedge, and the larger the trusted attenuation coefficient, the higher the risk propagation weight of the corresponding hyperedge.
6. The intelligent risk perception and linkage protection system for IoT terminals according to claim 5, characterized in that, The reliability decay coefficient is calculated by weighting the number of times the device certificate expires, the number of times the startup chain hash is inconsistent, the number of times the firmware hash is inconsistent, the number of times the authentication fails, and the duration of abnormal residuals. When the reliability attenuation coefficient exceeds a preset threshold, the propagation strength of the communication session superedge and service call superedge containing the corresponding IoT terminal is increased.
7. The intelligent risk perception and linkage protection system for IoT terminals according to claim 1, characterized in that, The entropy-regularized optimal transmission matching includes: using the risk trajectory state of each IoT terminal as the distribution to be matched, and using preset normal operation prototypes, reliable attenuation prototypes, lateral propagation prototypes, and environmentally induced anomaly prototypes as prototype distributions; constructing a transmission cost matrix based on the distance between the risk trajectory state and each risk prototype; solving the transmission matrix through entropy regularization terms; and determining the risk type and risk contribution of the IoT terminal based on the transmission cost of the corresponding lateral propagation prototype or reliable attenuation prototype in the transmission matrix.
8. The intelligent risk perception and linkage protection system for IoT terminals according to claim 7, characterized in that, The process of identifying risk source nodes includes: constructing a multidimensional anomaly event sequence by identifying the moments when the abnormal residuals in each IoT terminal exceed a threshold; calculating the anomaly triggering intensity among different IoT terminals by modulating the triggering kernel function of the Hawkes process using a reliable attenuation coefficient; identifying IoT terminals whose anomaly triggering intensity meets a preset condition as candidate risk source nodes; deleting the anomaly events corresponding to the candidate risk source nodes from the multidimensional anomaly event sequence and recalculating the anomaly occurrence probability of the affected nodes; and identifying the candidate risk source node with the largest decrease in anomaly occurrence probability before and after counterfactual deletion as the risk source node.
9. A smart risk perception and linkage protection system for IoT terminals according to claim 7, characterized in that, Generating at least two levels of coordinated protection actions includes: constructing a node risk diffusion equation based on a trusted gating temporal risk hypergraph to predict the risk concentration of each IoT terminal in future time steps; inputting the current risk concentration, predicted risk concentration, node business importance, risk contribution, and executable protection actions into the protection policy network to output a candidate coordinated protection action sequence; eliminating candidate coordinated protection actions that do not meet business continuity constraints through a security shielding layer; and selecting the target coordinated protection action sequence from the remaining candidate coordinated protection action sequences.
10. A smart risk perception and linkage protection system for IoT terminals according to claim 9, characterized in that, The security shielding layer sets prohibition conditions for different protection actions based on the importance of node services and service continuity constraints; When the target node is a critical business node and there is no backup node, it is prohibited to directly perform terminal isolation, network disconnection or firmware rollback operations. When the target node is a non-critical business node and its risk concentration exceeds the preset high-risk threshold, terminal isolation, gateway blocking, or firmware rollback operations are allowed.