Passive industrial control network topology discovery method and industrial control network security management system

A technology of industrial control network and discovery method, which is applied in the direction of transmission system, digital transmission system, data exchange network, etc., can solve the problems of topology integrity influence, large amount of information, useless information, etc., achieve accurate perception, realize security, realize management effect

Active Publication Date: 2020-02-18
BEIJING INSTITUTE OF TECHNOLOGYGY
View PDF7 Cites 7 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, although the passive monitoring method of obtaining all network communication packets by means of port mirroring can completely obtain its communication information, its disadvantages are: the amount of information obtained is large and complex, and most of it is useless information. Processing relevant data to obtain complete topology information will affect the integrity of its topology structure. Therefore, a fast and complete method for extracting network topology information is very important for obtaining complete network topology

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Passive industrial control network topology discovery method and industrial control network security management system
  • Passive industrial control network topology discovery method and industrial control network security management system
  • Passive industrial control network topology discovery method and industrial control network security management system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0048] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts all belong to the protection scope of the present invention.

[0049] The purpose of the present invention is to provide a passive industrial control network topology discovery method, which can quickly and completely determine the topology structure of the measured industrial control network. On this basis, an industrial control network security management method and system are provided, which can identify the operating system of the equipment in the industrial control network after determining the topolo...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a passive industrial control network topology discovery method and an industrial control network security management method and system. The passive industrial control network topology discovery method comprises the following steps: determining a core switch of a tested industrial control network; setting one port of the core switch as a mirror image port, and setting otherports as source ports; sniffing the communication data packet of the tested industrial control network through the mirror image port; carrying out dimension reduction processing on the sniffed data packet; classifying the data packets subjected to dimension reduction by adopting a CART classification tree model to obtain a classification result, wherein the classification result represents the connection type between the equipment represented by the source address of the data packet and the equipment represented by the destination address of the data packet, and the connection type comprises the connection between the switch and the router, the connection between the host and the switch and the connection between the switches; and determining the topological structure of the tested industrial control network according to the classification result. According to the invention, the topological structure of the tested industrial control network can be quickly and completely determined, andthe safety of the tested industrial control network is managed.

Description

technical field [0001] The invention relates to the fields of industrial control and network security, in particular to a passive industrial control network topology discovery method and an industrial control network security management system. Background technique [0002] With the introduction of the concept of "Industrial Internet" in the United States and the implementation of "Industry 4.0" in Germany, the integration of the two has become the general trend. Since the traditional industrial system only considered its practicality at the beginning of its construction and did not consider security issues, its vulnerability was completely exposed in the mutual integration with the Internet, resulting in an endless stream of network security incidents, especially for industrial control systems, etc. The invasion and attack of national infrastructure has seriously affected the national economy and people's livelihood of the country. Effectively detecting the network securit...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L12/24H04L29/06
CPCH04L41/12H04L63/1433H04L63/205
Inventor 张百海蓝敏迪庞中华柴森春崔灵果姚分喜
Owner BEIJING INSTITUTE OF TECHNOLOGYGY
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products