Unlock instant, AI-driven research and patent intelligence for your innovation.

Industrial control protocol field and semantic reverse inference method

An industrial control protocol and field technology, applied in semantic analysis, electrical digital data processing, redundant code error detection, etc., can solve the problems of semantic analysis failure, inaccurate field division, etc., and achieve safe and convenient use, scientific and reasonable structure, The effect of ensuring correctness

Pending Publication Date: 2020-09-29
NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT +1
View PDF6 Cites 1 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] The reverse analysis of unknown industrial control protocols mainly adopts the analysis method based on network traffic. This method is relatively general. It only needs to import the communication samples of the industrial control protocol into the analysis system in the form of pcap, and then the format of the industrial control protocol can be obtained by reverse analysis. And the state machine, the traditional method is to divide the message into fields first, and then infer the semantics of the fields according to the characteristics of each data in the fields. This method will cause the semantic analysis to fail due to the inaccurate field division. Combining the division of fields and the identification of semantics to analyze the lexical and grammar of the message, especially the semantic fields such as sequence number, timestamp, length, and check code have obvious characteristics, and the message can be analyzed based on these field features. Content matching, so as to realize the optimization and improvement of the industrial control protocol analysis results, therefore, a method for reverse inference of industrial control protocol fields and semantics is needed to solve the problems existing in the existing technology

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Industrial control protocol field and semantic reverse inference method
  • Industrial control protocol field and semantic reverse inference method

Examples

Experimental program
Comparison scheme
Effect test

Embodiment

[0028] Example: such as figure 1 As shown, an industrial control protocol field and semantic reverse inference method includes the following steps:

[0029] S1, import: read the pcap file, import all the message data in the pcap file, and load it into the message data set;

[0030] S2. Classification: Classify each message to generate different message sets;

[0031] S3, analysis: analyze the message of each type of collection byte by byte, the specific steps are:

[0032] a. Compare all messages by byte-by-byte comparison from beginning to end, infer the existence of the message protocol initiator field, and determine the range of the protocol initiator field;

[0033] b. Calculate the difference by byte-by-byte comparison for all messages, infer the existence of the sequence number field of the message, and determine the range of the sequence number field;

[0034] c. Calculate the difference in units of continuous four-byte length for all messages from the beginning to t...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses an industrial control protocol field and semantic reverse inference method. The method comprises the steps of importing, classifying, analyzing and matching. The structure is scientific and reasonable, safe and convenient use, messages are classified according to source IP addresses and lengths of the messages; classifying the messages with the same IP address and length into the same set; analyzing the messages of each type of sets byte by byte; and comparing the features of part of semantics with the features of bytes, wherein the bytes matched with the correspondingsemantics in the analyzed message are independent fields, and the semanteme of the field is the corresponding semanteme, so that the field and semanteme reverse inference of the industrial control protocol is realized, the problem of semantic analysis failure caused by inaccurate field division is solved, the lexical method and grammar of the protocol are accurately inferred, and the correctness of an analysis result is ensured.

Description

technical field [0001] The invention relates to the technical field of protocol format analysis, in particular to an industrial control protocol field and semantic reverse inference method. Background technique [0002] Industrial control system is an automatic control system composed of computer equipment and industrial process control components, widely used in electric power, water treatment, oil and gas, chemical industry, transportation, manufacturing and other industries. With the networking and informatization of industrial control systems, more and more industrial control devices are connected to the network, which brings great security risks while being convenient to use. In order to eliminate these security risks, it is necessary to use protocol reverse analysis Method, combined with fuzzy testing and other technologies to detect the industrial control protocol, so as to dig out whether there are security loopholes in the industrial control protocol. [0003] The ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): G06F40/30G06F11/10G06F16/33
CPCG06F40/30G06F11/1004G06F16/3331
Inventor 张晓明何跃鹰孙中豪张嘉玮曹可建王占丰马玮骏毛传奇
Owner NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT