The invention belongs to the technical field of computers, and particularly relates to an
Internet of Things security data real-time monitoring and protection method and
system, and the method comprises the steps: collecting equipment communication and state data through an edge agent, and analyzing and extracting standardized
metadata; constructing an equipment behavior contour vector based on a sliding window, and dynamically maintaining a global equipment
topological graph; triggering a primary alarm in combination with behavior deviation detection and topology abnormity; outputting a
threat score and an
attack intention through
rule matching and
Bayesian network double-engine collaborative reasoning; and executing automatic response according to grading, and feeding back and correcting a behavior baseline to realize closed-
loop optimization. The
system comprises a
data acquisition module, a protocol analysis module, a behavior modeling module, a topology maintenance module, an
anomaly detection module, a collaborative reasoning module, an automatic response module and a baseline correction module. Through full-link real-time modeling and cross-device collaborative analysis, the
attack detection rate is significantly increased to 98% or above, the
false alarm rate is lower than 2%, the
response delay is controlled within 800 milliseconds, and the security and adaptive ability of
the Internet of Things
system are enhanced.