Industrial control network security service security guarantee system based on behavior analysis

Through a comprehensive protection system of multi-source data fusion, dynamic modeling, federated learning and adaptive protection, the static and response lag problems of industrial control network security systems are solved, and efficient, real-time security protection and business continuity guarantee for industrial control networks are achieved.

CN120474776AActive Publication Date: 2025-08-12CPI NORTHEAST ENERGY SAVING TECH +1

Patent Information

Application Number
CN202510607332.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-08-12
Estimated Expiration
2045-05-13

AI Technical Summary

Technical Problem

The existing industrial control network security service security guarantee system has problems such as static rule dependence, insufficient single-dimensional analysis, lag in response and high false alarm rates. It is difficult to adapt to the dynamically changing industrial control environment and new attack modes, and is prone to production interruptions due to error blocking.

Method used

The multi-source data fusion acquisition module, dynamic behavior modeling engine, federated learning analysis cluster, attack chain prediction module and adaptive protection strategy executor are adopted, combining software-defined security architecture and model evolution feedback loop to achieve real-time protection and optimization.

Benefits of technology

It significantly improves the proactive defense capabilities of advanced persistent threats and zero-day attacks, reduces the risk of misjudgment, ensures the continuity and security of industrial control business, and meets the millisecond response needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474776A_ABST
    Figure CN120474776A_ABST
Patent Text Reader

Abstract

The invention provides an industrial control network security service security guarantee system based on behavior analysis, which belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, a self-adaptive protection strategy executor and a model evolution feedback ring, wherein the multi-source data fusion acquisition module synchronously acquires industrial control network flow (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints and physical interface state data, and the physical interface state data comprises electrical characteristic fluctuation monitoring of USB / network interfaces. According to the scheme, through multi-technology fusion and closed-loop design, the problems of static performance, single-dimension analysis defects and response lag of a traditional industrial control security scheme are effectively solved, a comprehensive protection system with dynamic modeling, intelligent decision making, privacy protection and continuous optimization is constructed, and the security and service reliability of an industrial control network are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial control network security, and in particular to an industrial control network security business security assurance system based on behavior analysis. Background Art

[0002] The Industrial Control Network Security Business Security Assurance System is a security protection system designed specifically for industrial control systems. It aims to defend against threats such as cyberattacks and malicious operations, ensuring stable industrial production and business continuity. Its core is to ensure the security and controllability of industrial control business operations, preventing production losses or data leaks caused by security risks. Existing Industrial Control Network Security Business Security Assurance Systems still have the following shortcomings:

[0003] 1. Static rule reliance: Traditional solutions rely primarily on predefined rule bases or single risk assessment models, making them difficult to adapt to dynamically changing industrial control environments and new attack patterns.

[0004] 2. Insufficient single-dimensional analysis: Lack of multi-dimensional correlation analysis of user behavior, device status, and network traffic leads to weak threat tracing capabilities;

[0005] 3. Delayed response and high false alarm rate: Insufficient dynamic baseline modeling and adaptive strategies result in a high false alarm rate and low efficiency in the execution of protection strategies.

[0006] Technology development needs:

[0007] Balancing data privacy and model generalization: Industrial control nodes have high data privacy requirements, and collaborative model training must be achieved while protecting data.

[0008] Improved real-time performance and accuracy: Industrial control systems have strict real-time requirements, requiring millisecond-level protection policy delivery and high-precision attack prediction;

[0009] Business continuity assurance: Traditional solutions are prone to production interruptions due to erroneous blocking, and require a combination of virtual verification and policy conflict resolution to optimize protection logic.

[0010] Therefore, an industrial control network security business security assurance system based on behavior analysis is proposed. Summary of the Invention

[0011] The present invention aims to solve the problems raised in the background technology and provides an industrial control network security business security assurance system based on behavior analysis.

[0012] The specific technical solutions are as follows:

[0013] An industrial control network security business security assurance system based on behavior analysis, comprising:

[0014] The multi-source data fusion acquisition module simultaneously acquires industrial control network traffic (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints, and physical interface status data, including electrical characteristic fluctuation monitoring of USB / network interfaces.

[0015] The dynamic behavior modeling engine uses a heterogeneous data processing pipeline to encode device status data (PLC register values, sensor sampling rates) and user behavior data (operation instruction sequences, permission change records), and then fuses them through a spatiotemporal attention mechanism to generate a three-dimensional behavior baseline model.

[0016] The federated learning analysis cluster consists of edge computing units deployed on each industrial control node. It uses differential privacy technology to encrypt local behavior features, implements cross-domain model aggregation through parameter servers, and outputs a global abnormal behavior map.

[0017] The attack chain prediction module integrates the Hidden Markov Model (HMM) and Graph Neural Network (GNN) to predict potential attack paths based on real-time behavioral deviations and generate threat intelligence including attack stage identification (reconnaissance, lateral movement, data exfiltration);

[0018] Adaptive protection policy executor, based on the software-defined security (SDS) architecture, dynamically reconstructs access control rules and supports millisecond-level delivery and rollback of protection policies, including triple protection mechanisms such as traffic rate limiting, port isolation, and instruction whitelisting.

[0019] The model evolution feedback loop optimizes the federated learning aggregation weights through reinforcement learning and adopts adversarial sample generation technology to enhance the robustness of the baseline model against zero-day attacks.

[0020] In the above-mentioned industrial control network security business security assurance system based on behavioral analysis, the multi-source data fusion acquisition module is connected to the industrial control network in parallel through the industrial bus (such as PROFINET) and the mirror port, and its output end is connected to the heterogeneous data input interface of the dynamic behavior modeling engine;

[0021] The dynamic behavior modeling engine receives real-time data streams from the multi-source data fusion acquisition module. Its baseline model output is connected to the local model upload interface of the federated learning analysis cluster via the OPC UA protocol, and provides behavior deviation indicators to the attack chain prediction module.

[0022] Each edge computing unit in the federated learning analysis cluster is connected to the central parameter server via a time-sensitive network (TSN). Its global anomaly graph generation end is connected to the threat intelligence fusion layer of the attack chain prediction module via a RESTful API.

[0023] The attack chain prediction module receives real-time deviation data from the dynamic behavior modeling engine and the global anomaly map from the federated learning analysis cluster. Its attack path prediction results are pushed to the policy decision engine of the adaptive protection policy executor via the message queue (MQTT);

[0024] The adaptive protection policy executor includes an OpenFlow interface directly connected to the control plane switch and an execution result feedback channel, including:

[0025] The protection policy delivery interface is synchronized in real time with the SDN controller in the industrial control network;

[0026] The policy execution effect data is transmitted back to the model evolution feedback loop via the data plane collection agent;

[0027] The model evolution feedback loop establishes a two-way data channel with the weight adjustment interface of the dynamic behavior modeling engine and the aggregation algorithm update interface of the federated learning analysis cluster through a cross-layer feedback bus, forming a closed-loop optimization mechanism.

[0028] In the above-mentioned industrial control network security and business security assurance system based on behavior analysis, the multi-source data fusion acquisition module includes:

[0029] The physical interface security protection unit uses a Y-shaped metal limit bar and piezoelectric sensor composite structure. When unauthorized plug-in or plug-out operations are detected, the physical locking mechanism and digital certificate revocation are triggered simultaneously.

[0030] The protocol deep parsing unit supports instruction-level reorganization of industrial control protocols transmitted on non-standard ports, and identifies abnormal payloads disguised as legitimate protocols through syntax tree comparison.

[0031] The above-mentioned industrial control network security and business security assurance system based on behavior analysis, wherein the dynamic behavior modeling engine includes:

[0032] The device profile generation unit builds differentiated behavior evaluation indicators based on device type (PLC / RTU / HMI), where the PLC controller adds a register write frequency weighting factor;

[0033] The user behavior baseline library establishes a multi-level operation sequence Markov chain based on role permissions (operator / administrator / third party), and implements double behavior verification for high-risk operations (such as firmware upgrades and clock synchronization).

[0034] In the above-mentioned industrial control network security business security assurance system based on behavioral analysis, the federated learning analysis cluster adopts:

[0035] Gradient obfuscation mechanism, which injects Gaussian noise during local model training to ensure that the original data characteristics cannot be restored during parameter updates;

[0036] Dynamic participating node selection algorithm dynamically adjusts federated learning participating nodes based on device online status, computing resource margin, and security posture score.

[0037] In the above-mentioned industrial control network security service security assurance system based on behavior analysis, the attack chain prediction module implements:

[0038] Multi-stage attack correlation analysis: causal reasoning is performed between abnormal device states (such as sudden changes in temperature sensor data) and network behaviors (such as abnormal external connections to the SCADA server), generating an attack stage assessment report mapped to the MITRE ATT&CK framework.

[0039] The risk quantification decision matrix uses the analytic hierarchy process (AHP) to calculate the threat value of each attack path:

[0040]

[0041] where w i is the attack phase weight, S i is the current behavior deviation, k is the situation sensitivity coefficient, and S0 is the baseline deviation threshold.

[0042] In the above-mentioned industrial control network security business security assurance system based on behavior analysis, the adaptive protection strategy executor includes:

[0043] The digital twin verification sandbox performs virtual execution of suspicious control instructions and confirms attack behavior by comparing the state deviation value (Δ>15%) between the actual device and the digital twin;

[0044] The policy conflict resolver automatically selects the optimal execution plan based on business continuity priority when multiple protection policies are mutually exclusive (such as isolation and mirroring are triggered at the same time).

[0045] In the above-mentioned industrial control network security business security assurance system based on behavioral analysis, the model evolution feedback loop implements:

[0046] Adversarial example evolution mechanism, using Wasserstein GAN to generate adversarial examples that conform to the physical constraints of industrial control, enhancing the model's ability to identify covert attacks;

[0047] The incremental learning scheduler automatically triggers local model retraining based on device firmware upgrade records to maintain version consistency between the behavioral baseline model and the physical device.

[0048] In the above-mentioned industrial control network security service security assurance system based on behavior analysis, the physical interface security protection unit integrates:

[0049] Multimodal authentication module, which requires simultaneous verification of the digital certificate (SM2 algorithm) and the physical key (NFC chip) during physical connection, activating a self-destruct fuse circuit if authentication fails;

[0050] The electromagnetic fingerprint collection unit establishes a unique identification library for the device hardware by monitoring the electromagnetic radiation characteristics when the interface is connected.

[0051] In the above-mentioned industrial control network security business security assurance system based on behavior analysis, the user behavior baseline library implements:

[0052] Dual-factor behavior verification couples user biometrics (finger vein recognition) with operation timing patterns (click intervals, command combinations) for verification;

[0053] Context-aware correction automatically adjusts the permitted operation time window based on production plan changes, and implements a four-eye approval principle for high-risk operations during unplanned periods;

[0054] In the above-mentioned industrial control network security business security assurance system based on behavior analysis, the risk quantification decision matrix introduces:

[0055] Business impact factors dynamically adjust risk calculation weights based on the process importance of the protected equipment (e.g., reactor pressure control vs. environmental monitoring);

[0056] The situation propagation model calculates the probability of cascading failures caused by single-point anomalies based on the industrial control network topology.

[0057] The present invention has the following beneficial effects:

[0058] 1. Full-chain collaborative protection: By integrating multi-source data collection, dynamic behavior modeling, federated learning analysis, attack chain prediction, adaptive protection, and model evolution feedback modules, a closed-loop protection system covering the entire process of "data collection-analysis-decision-execution-optimization" has been built, significantly improving the proactive defense capabilities against advanced persistent threats (APTs) and zero-day attacks.

[0059] 2. Multi-dimensional security assurance:

[0060] Physical layer defense: effectively prevents hardware counterfeit attacks through physical interface security protection units and unauthorized operation detection;

[0061] Protocol layer deep detection: supports non-standard port protocol reassembly and abnormal payload identification, improving the detection accuracy of protocol masquerade attacks;

[0062] Dynamic modeling at the behavioral layer: Differentiated device portraits and user behavior baseline libraries enhance the ability to distinguish between legitimate operations and abnormal behaviors, reducing the risk of misjudgment.

[0063] 3. Intelligent decision-making and adaptive optimization:

[0064] The privacy protection mechanism based on federated learning enables cross-node collaborative analysis, ensuring model generalization capabilities while protecting data privacy;

[0065] Through digital twin sandbox verification and policy conflict resolution, the false blocking rate is reduced and industrial control business continuity is guaranteed;

[0066] The dynamic sensitivity coefficient is combined with the risk quantification model to enhance the response sensitivity to sudden attacks.

[0067] 4. Improved system robustness:

[0068] The model evolution feedback loop continuously optimizes the baseline model through adversarial sample generation and incremental learning to adapt to industrial control equipment firmware upgrades and new attack modes;

[0069] Based on risk assessment of business impact factors and situation propagation models, abnormal behaviors that may cause cascading failures can be blocked in advance. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] Figure 1 A schematic diagram of the architecture of an industrial control network security and business security assurance system based on behavior analysis provided by an embodiment of the present invention;

[0071] Figure 2 A diagram showing the influence of the dynamic sensitivity coefficient k on the response time of the industrial control network security and service security assurance system based on behavior analysis provided by an embodiment of the present invention;

[0072] Figure 3 This is a comparison chart of errors in the improved normalization method of the industrial control network security and business security assurance system based on behavior analysis provided by an embodiment of the present invention;

[0073] Figure 4 A comparison chart of attack recognition accuracy of the industrial control network security and business security assurance system based on behavior analysis provided by an embodiment of the present invention;

[0074] Figure 5 A comparison chart of the false blocking rates of the industrial control network security service security assurance system based on behavior analysis provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0075] The technical solution of the present invention will be further described below with reference to the accompanying drawings and through specific implementation methods.

[0076] Among them, the drawings are only used for illustrative purposes and represent only schematic diagrams rather than actual pictures, and should not be understood as limiting this patent; in order to better illustrate the embodiments of the present invention, some parts of the drawings may be omitted, enlarged or reduced, and do not represent the size of the actual product; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the drawings may be omitted.

[0077] The same or similar numbers in the drawings of the embodiments of the present invention correspond to the same or similar parts; in the description of the present invention, it should be understood that if the terms "upper", "lower", "left", "right", "inside", "outside" and the like indicate an orientation or position relationship based on the orientation or position relationship shown in the drawings, it is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation. Therefore, the terms describing the position relationship in the drawings are only used for illustrative purposes and cannot be understood as limiting this patent. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to specific circumstances.

[0078] In the description of the present invention, unless otherwise expressly specified or limited, when the term "connection" or the like appears to indicate a connection relationship between components, such term should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be internal communication between two components or an interaction between two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood in specific circumstances.

[0079] This embodiment provides an industrial control network security service security assurance system based on behavior analysis, such as Figure 1-Figure 5 As shown, Figure 2 The following diagram shows the impact of the dynamic sensitivity coefficient k on response time. Assuming the industry average response time is 100ms, this system reduces the response time to one-fifth of the industry average by dynamically adjusting the sensitivity coefficient k, significantly improving the system's response speed. Figure 3 This chart compares the error performance of the improved normalization method using the traditional Min-Max normalization method and the improved Tanh normalization method in a data distribution shift scenario. Assuming the traditional method has a 15% error, the improved method reduces the error to 5% by optimizing the normalization process, significantly improving data processing accuracy. Figure 4This attack identification accuracy comparison chart shows the attack identification accuracy of a traditional solution and our system in a StealthyFDI attack scenario. The traditional solution has an accuracy of 89.2%, while our system achieves an accuracy of 98.7%, significantly improving attack identification accuracy. Figure 5 The following chart compares the false blocking rate with the industry benchmark and our system. The industry benchmark has a false blocking rate of 9.1%, while our system has reduced this rate to 2.3% through algorithm optimization, significantly reducing the occurrence of false operations.

[0080] The industrial control network security business security assurance system based on behavioral analysis includes: a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federated learning analysis cluster, an attack chain prediction module, an adaptive protection strategy executor, and a model evolution feedback loop, among which:

[0081] The multi-source data fusion acquisition module simultaneously acquires industrial control network traffic (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints, and physical interface status data, including electrical characteristic fluctuation monitoring of USB / network interfaces.

[0082] The dynamic behavior modeling engine uses a heterogeneous data processing pipeline to encode device status data (PLC register values, sensor sampling rates) and user behavior data (operation instruction sequences, permission change records), and then fuses them through a spatiotemporal attention mechanism to generate a three-dimensional behavior baseline model.

[0083] The federated learning analysis cluster consists of edge computing units deployed on each industrial control node. It uses differential privacy technology to encrypt local behavior features, implements cross-domain model aggregation through parameter servers, and outputs a global abnormal behavior map.

[0084] The attack chain prediction module integrates the Hidden Markov Model (HMM) and Graph Neural Network (GNN) to predict potential attack paths based on real-time behavioral deviations and generate threat intelligence including attack stage identification (reconnaissance, lateral movement, data exfiltration);

[0085] Adaptive protection policy executor, based on the software-defined security (SDS) architecture, dynamically reconstructs access control rules and supports millisecond-level delivery and rollback of protection policies, including triple protection mechanisms such as traffic rate limiting, port isolation, and instruction whitelisting.

[0086] The model evolution feedback loop optimizes the federated learning aggregation weights through reinforcement learning and adopts adversarial sample generation technology to enhance the robustness of the baseline model against zero-day attacks.

[0087] The behavioral analysis-based industrial control network security business security assurance system that adopts the above-mentioned technical solution integrates multi-source data collection, dynamic modeling, federated learning, attack prediction, adaptive protection and feedback optimization modules to build a collaborative protection system covering the entire chain, thereby improving the industrial control system's active defense capabilities against complex attacks and ensuring business continuity.

[0088] Specifically, in this embodiment, the multi-source data fusion acquisition module is connected to the industrial control network in parallel via an industrial bus (such as PROFINET) and a mirror port, and its output end is connected to the heterogeneous data input interface of the dynamic behavior modeling engine;

[0089] The dynamic behavior modeling engine receives real-time data streams from the multi-source data fusion acquisition module. Its baseline model output is connected to the local model upload interface of the federated learning analysis cluster via the OPC UA protocol, and provides behavior deviation indicators to the attack chain prediction module.

[0090] Each edge computing unit in the federated learning analysis cluster is connected to the central parameter server via a time-sensitive network (TSN). Its global anomaly graph generation end is connected to the threat intelligence fusion layer of the attack chain prediction module via a RESTful API.

[0091] The attack chain prediction module receives real-time deviation data from the dynamic behavior modeling engine and the global anomaly map from the federated learning analysis cluster. Its attack path prediction results are pushed to the policy decision engine of the adaptive protection policy executor via the message queue (MQTT);

[0092] The adaptive protection policy executor includes an OpenFlow interface directly connected to the control plane switch and an execution result feedback channel, including:

[0093] The protection policy delivery interface is synchronized in real time with the SDN controller in the industrial control network;

[0094] The policy execution effect data is transmitted back to the model evolution feedback loop via the data plane collection agent;

[0095] The model evolution feedback loop establishes a two-way data channel with the weight adjustment interface of the dynamic behavior modeling engine and the aggregation algorithm update interface of the federated learning analysis cluster through a cross-layer feedback bus, forming a closed-loop optimization mechanism.

[0096] The above technical solution ensures efficient collaboration between system modules through parallel access of the industrial bus and mirror port, time-sensitive network transmission, and cross-layer feedback mechanism, achieving real-time closed-loop response of data collection, analysis and decision-making, and strategy execution.

[0097] Specifically, in this embodiment, the multi-source data fusion acquisition module includes:

[0098] The physical interface security protection unit uses a Y-shaped metal limit bar and piezoelectric sensor composite structure. When unauthorized plug-in or plug-out operations are detected, the physical locking mechanism and digital certificate revocation are triggered simultaneously.

[0099] The protocol deep parsing unit supports instruction-level reorganization of industrial control protocols transmitted on non-standard ports, and identifies abnormal payloads disguised as legitimate protocols through syntax tree comparison.

[0100] The above technical solutions are used to enhance the physical layer security protection capabilities, effectively prevent unauthorized devices from accessing, and improve the detection accuracy of protocol spoofing attacks, preventing abnormal commands from penetrating into the industrial control network.

[0101] Specifically, in this embodiment, the dynamic behavior modeling engine includes:

[0102] The device profile generation unit builds differentiated behavior evaluation indicators based on device type (PLC / RTU / HMI), where the PLC controller adds a register write frequency weighting factor;

[0103] The user behavior baseline library establishes a multi-level operation sequence Markov chain based on role permissions (operator / administrator / third party), and implements double behavior verification for high-risk operations (such as firmware upgrades and clock synchronization).

[0104] By adopting the above technical solutions, we can achieve differentiated modeling of device behavior portraits and fine-grained control of user operations, improve the adaptability of the baseline model to device types and role permissions, and reduce the risk of misjudgment.

[0105] Specifically, in this embodiment, the federated learning analysis cluster adopts:

[0106] Gradient obfuscation mechanism, which injects Gaussian noise during local model training to ensure that the original data characteristics cannot be restored during parameter updates;

[0107] Dynamic participating node selection algorithm dynamically adjusts federated learning participating nodes based on device online status, computing resource margin, and security posture score.

[0108] By adopting the above technical solutions, the efficiency of federated learning can be optimized while protecting data privacy, and participating nodes can be dynamically adjusted to adapt to changes in the industrial control environment, ensuring the security and resource utilization of model training.

[0109] Specifically, in this embodiment, the attack chain prediction module implements:

[0110] Multi-stage attack correlation analysis: causal reasoning is performed between abnormal device states (such as sudden changes in temperature sensor data) and network behaviors (such as abnormal external connections to the SCADA server), generating an attack stage assessment report mapped to the MITRE ATT&CK framework.

[0111] The risk quantification decision matrix uses the analytic hierarchy process (AHP) to calculate the threat value of each attack path:

[0112]

[0113] where w i is the attack phase weight, S i is the current behavior deviation, k is the situation sensitivity coefficient, and S0 is the baseline deviation threshold.

[0114] By adopting the above technical solutions, we can integrate multi-dimensional abnormal characteristics with attack framework knowledge, enhance the prediction ability of multi-stage attack chains, and realize the quantitative assessment and priority division of risk threats.

[0115] The parameters of the risk quantification decision matrix are defined as follows:

[0116] 1. Attack phase weight w i :

[0117] Technical Definition: Based on the attack phases (reconnaissance, weaponization, lateral movement, etc.) of the MITRE ATT&CK framework, this is calculated using a judgment matrix constructed using the Analytic Hierarchy Process (AHP). The scale of the judgment matrix is derived from the device criticality score (CVE vulnerability level × business impact factor).

[0118] Dynamic adjustment mechanism:

[0119] Initial value: Preset the benchmark weight according to the device type (PLC controller weight range [0.3, 0.6], HMI human-machine interface [0.1, 0.3]);

[0120] Runtime correction: A sliding average calculation is performed every 24 hours based on the attack pattern popularity updated by threat intelligence subscription services (such as the MISP platform);

[0121] 2. Current behavior deviation S i :

[0122] Computational model:

[0123]

[0124] Where V current is the real-time behavior feature vector V baseline is the baseline model output, σ historical is the standard deviation of historical data, =1e -5 Prevent division by zero errors;

[0125] Normalization: Use the improved Tanh function to normalize S i Mapping to the interval [0,1]:

[0126]

[0127] 3. Situation sensitivity coefficient k:

[0128] Dynamic calculation equation:

[0129]

[0130] k base : Basic sensitivity (default value 2.5, configurable range [1.0, 5.0]);

[0131] α: Environmental threat coefficient (obtained through real-time threat intelligence interface, value range [0.1, 0.9])

[0132] N alert : The number of alarms triggered in the current attack chain;

[0133] N total : The total number of stages in the attack chain;

[0134] Mechanism: When the attack chain completion rate exceeds 30%, the kk value is automatically increased by 1.8 times to enhance the risk perception sensitivity.

[0135] 4. Baseline deviation threshold S0:

[0136] Generation method:

[0137] Offline stage: Calculate the upper bound of the 95% confidence interval of the historical normal data distribution through kernel density estimation (KDE);

[0138] Online stage: Update using exponential weighted moving average (EWMA):

[0139]

[0140] Among them, the smoothing factor λ = 0.85 (configurable range [0.7, 0.95]);

[0141] Abnormal reset: When S i > 2S0 for 3 consecutive times, trigger the emergency reconstruction process of the baseline model;

[0142] 5. Nonlinear transformation function:

[0143] Technical effect: Using the sigmoid function to replace the traditional linear superposition to solve the following problems:

[0144] Inhibitory effect on low-deviation attacks (S i < S0) (output value < 0.5);

[0145] Saturation characteristics of high-deviation attacks (S i > 2S0) (output value approaches 1);

[0146] Engineering optimization: Use linear interpolation transition within the range of S0±0.2 to avoid strategy oscillation caused by sudden inflection point changes.

[0147] This solution combines AHP weights with real-time threat intelligence, significantly improving the APT attack detection rate; the introduction of the dynamic sensitivity coefficient k significantly shortens the response time to sudden attacks from the industry average; the improved Tanh normalization method significantly reduces the error in data distribution offset scenarios compared to traditional Min-Max normalization; the EWMA threshold update mechanism significantly reduces the false alarm rate compared to the fixed threshold solution.

[0148] Technical effectiveness verification: After testing on the OPC UA testbed, this parameter system has the following performance in the Stealthy FDI attack scenario:

[0149] Attack identification accuracy: 98.7% (compared to 89.2% for traditional solutions);

[0150] False blocking rate: 2.3% (compared to the industry benchmark of 9.1%);

[0151] Meets the enhanced requirements of SR 3.8 (anomaly detection) and SR 3.10 (risk assessment) in the IEC 62443-3-3 standard.

[0152] Specifically, in this embodiment, the adaptive protection strategy executor includes:

[0153] The digital twin verification sandbox performs virtual execution of suspicious control instructions and confirms attack behavior by comparing the state deviation value (Δ>15%) between the actual device and the digital twin;

[0154] The policy conflict resolver automatically selects the optimal execution plan based on business continuity priority when multiple protection policies are mutually exclusive (such as isolation and mirroring are triggered at the same time).

[0155] By adopting the above technical solution, the effectiveness of the strategy is verified through virtual execution, and the strategy conflicts are resolved intelligently, thus maintaining the normal operation of industrial control business to the greatest extent while ensuring security protection.

[0156] Specifically, in this embodiment, the model evolution feedback loop implements:

[0157] Adversarial example evolution mechanism, using Wasserstein GAN to generate adversarial examples that conform to the physical constraints of industrial control, enhancing the model's ability to identify covert attacks;

[0158] The incremental learning scheduler automatically triggers local model retraining based on device firmware upgrade records to maintain version consistency between the behavioral baseline model and the physical device.

[0159] The above technical solutions are used to improve the model's ability to generalize to new attack patterns, ensure the dynamic synchronization of the baseline model and the device firmware version, and avoid protection failures caused by system upgrades.

[0160] Specifically, in this embodiment, the physical interface security protection unit integrates:

[0161] Multimodal authentication module, which requires simultaneous verification of the digital certificate (SM2 algorithm) and the physical key (NFC chip) during physical connection, activating a self-destruct fuse circuit if authentication fails;

[0162] The electromagnetic fingerprint collection unit establishes a unique identification library for the device hardware by monitoring the electromagnetic radiation characteristics when the interface is connected.

[0163] The above technical solution is used to strengthen the multi-factor authentication and hardware uniqueness identification of the physical interface, effectively defend against physical layer counterfeit attacks, and improve the traceability of interface operations.

[0164] Specifically, in this embodiment, the user behavior baseline library implements:

[0165] Dual-factor behavior verification couples user biometrics (finger vein recognition) with operation timing patterns (click intervals, command combinations) for verification;

[0166] Context-aware correction automatically adjusts the allowed operation time window according to changes in production plans, and implements the four-eye principle for approval of high-risk operations in unplanned periods.

[0167] By adopting the above technical solution, combined with dual verification of biometrics and operational behavior, it can dynamically adapt to changes in the production environment and achieve precise control and audit tracking of high-risk operations.

[0168] Specifically, in this embodiment, the risk quantification decision matrix introduces:

[0169] Business impact factors dynamically adjust risk calculation weights based on the process importance of the protected equipment (e.g., reactor pressure control vs. environmental monitoring);

[0170] The situation propagation model calculates the probability of cascading failures caused by single-point anomalies based on the industrial control network topology.

[0171] By adopting the above technical solution and introducing business logic and network topology correlation analysis, risk assessment can be more closely aligned with actual production needs, and abnormal behaviors that may cause cascading failures can be blocked in advance.

[0172] Among them, the spatiotemporal attention mechanism realizes multi-dimensional data fusion through the spatiotemporal anomaly perception fusion weight equation (STAFW), which is:

[0173]

[0174] in:

[0175] A i,j represents the fusion weight of device i in time window j, which is used to dynamically adjust the contribution of device behavior characteristics in the baseline model;

[0176] ΔT i is the time dynamic factor, and the standard deviation of the device state sequence is calculated through the sliding window;

[0177] Φ i,j is the spatial correlation factor, which is calculated based on the inverse of the shortest path hop count between devices in the industrial control network topology;

[0178] is the abnormality factor, representing the real-time feature vector V i Compared with the baseline model output The Euclidean distance of

[0179] σ i is the standard deviation of historical data of device i;

[0180] λ t ,λ s ,λ a are configurable hyperparameters that control the weights of time, space, and anomaly dimensions, respectively. (Default value: λ t =0.4,λ s =0.3,λ a =0.3).

[0181] τ and η are normalization coefficients used to balance the dimensional differences of each factor and prevent numerical overflow (τ = 10ms, η = 5).

[0182] For example, in the dynamic behavior modeling engine, suppose a PLC controller detects a sudden change in register value (ΔT i =8.2), and the logical distance to the SCADA server is 2 hops (Φ i,j =0.6), and the real-time features deviate from the baseline Substitute into the equation to calculate:

[0183]

[0184] The results show that the device's features are given high weights when fused, triggering deep anomaly analysis.

[0185] Technical effects:

[0186] Dynamic weight allocation: By combining time, space and abnormal factors, it can accurately capture sudden and correlated abnormal behaviors in industrial control systems.

[0187] Reduced false alarm rate: Compared with the traditional mean fusion method, the false alarm rate is significantly reduced in the StealthyFDI attack scenario.

[0188] Real-time optimization: The normalization coefficient design keeps the computational complexity at O(N), meeting the millisecond-level response requirements of industrial control systems.

[0189] The spatiotemporal attention mechanism implements the multi-dimensional data fusion workflow through the spatiotemporal anomaly-aware fusion weight equation (STAFW):

[0190] 1. Data preprocessing: real-time collection of device status (such as PLC register values) and network topology data;

[0191] 2. Factor calculation:

[0192] Time dynamic factor ΔT i : Calculate the standard deviation of the state sequence through a sliding window (such as 1s);

[0193] Spatial correlation factor Φ i,j :Calculate the inverse of the shortest path between devices based on the network topology (such as Φ i,j =1 / number of hops);

[0194] Anomaly factor: Real-time comparison of the deviation between the feature vector and the baseline model.

[0195] 3. Weight fusion: Substitute each factor into the STAFW equation to generate a weighted behavioral feature vector.

[0196] 4. Baseline model update: The spatiotemporal attention mechanism dynamically adjusts the generation process of the three-dimensional behavior baseline based on the weight. By incorporating the network topology correlation into the fusion weight, the problem of traditional methods ignoring the logical dependencies between devices is solved. i Dynamically normalize the abnormality to avoid misjudgment due to inherent fluctuations in the equipment. Hyperparameter λ t ,λ s ,λ a Support operation and maintenance personnel to flexibly adjust detection sensitivity according to business needs.

[0197] In summary, the industrial control network security service security assurance system based on behavior analysis provided by this embodiment has the following advantages:

[0198] 1. Full-chain collaborative protection: By integrating multi-source data collection, dynamic behavior modeling, federated learning analysis, attack chain prediction, adaptive protection, and model evolution feedback modules, a closed-loop protection system covering the entire process of "data collection-analysis-decision-execution-optimization" has been built, significantly improving the proactive defense capabilities against advanced persistent threats (APTs) and zero-day attacks.

[0199] 2. Multi-dimensional security assurance:

[0200] Physical layer defense: effectively prevents hardware counterfeit attacks through physical interface security protection units and unauthorized operation detection;

[0201] Protocol layer deep detection: supports non-standard port protocol reassembly and abnormal payload identification, improving the detection accuracy of protocol masquerade attacks;

[0202] Dynamic modeling at the behavioral layer: Differentiated device portraits and user behavior baseline libraries enhance the ability to distinguish between legitimate operations and abnormal behaviors, reducing the risk of misjudgment.

[0203] 3. Intelligent decision-making and adaptive optimization:

[0204] The privacy protection mechanism based on federated learning enables cross-node collaborative analysis, ensuring model generalization capabilities while protecting data privacy;

[0205] Through digital twin sandbox verification and policy conflict resolution, the false blocking rate is reduced and industrial control business continuity is guaranteed;

[0206] The dynamic sensitivity coefficient is combined with the risk quantification model to enhance the response sensitivity to sudden attacks.

[0207] 4. Improved system robustness:

[0208] The model evolution feedback loop continuously optimizes the baseline model through adversarial sample generation and incremental learning to adapt to industrial control equipment firmware upgrades and new attack modes;

[0209] Based on risk assessment of business impact factors and situation propagation models, abnormal behaviors that may cause cascading failures can be blocked in advance.

[0210] The specific workflow is as follows

[0211] 1. Data collection and fusion:

[0212] Access the industrial control network in parallel through the industrial bus (such as PROFINET) and the mirror port to capture multi-source data (network traffic, device logs, user operations, physical interface status) in real time;

[0213] The physical interface security protection unit simultaneously monitors illegal plug-in and unplugging behaviors, and the protocol parsing unit reorganizes industrial control instructions transmitted by non-standard ports.

[0214] 2. Dynamic behavior modeling:

[0215] Heterogeneous data processing pipelines encode device states (e.g., PLC register values) and user behaviors (e.g., sequences of operating instructions) separately;

[0216] The spatiotemporal attention mechanism fuses multi-dimensional data to generate a three-dimensional behavior baseline model.

[0217] 3. Federated Learning and Threat Prediction:

[0218] Edge computing nodes use differential privacy technology to encrypt local features and aggregate global anomaly graphs through time-sensitive networks (TSN);

[0219] The attack chain prediction module combines HMM and GNN to analyze the correlation between device abnormal status and network behavior and generate an attack stage assessment report.

[0220] 4. Adaptive protection execution:

[0221] Dynamically deliver protection policies (such as traffic rate limiting and port isolation) based on software-defined security (SDS);

[0222] The digital twin sandbox virtually executes suspicious instructions and verifies the authenticity of the attack through state deviation;

[0223] The policy conflict resolver selects the optimal execution plan based on business priorities.

[0224] 5. Closed-loop optimization and evolution:

[0225] The model evolution feedback loop optimizes federated learning weights through reinforcement learning and enhances model robustness using adversarial examples;

[0226] The incremental learning scheduler triggers local model retraining based on device firmware upgrade records to keep the system dynamically synchronized.

[0227] Through multi-technology integration and closed-loop design, this solution effectively addresses the static nature, single-dimensional analysis flaws, and delayed response issues of traditional industrial control security solutions. It builds a comprehensive protection system with dynamic modeling, intelligent decision-making, privacy protection, and continuous optimization, significantly improving the security and business reliability of industrial control networks.

[0228] The above are only preferred embodiments of the present invention and do not limit the implementation mode and protection scope of the present invention. For those skilled in the art, it should be aware that all solutions obtained by equivalent substitutions and obvious changes made using the description and illustrations of the present invention should be included in the protection scope of the present invention.

Claims

1. An industrial control network security business security assurance system based on behavior analysis, characterized in that: include: The multi-source data fusion acquisition module synchronously acquires industrial control network traffic, equipment operation logs, user operation behavior fingerprints, and physical interface status data, where the physical interface status data includes the electrical characteristic fluctuation monitoring of USB / network interfaces; The dynamic behavior modeling engine uses a heterogeneous data processing pipeline to encode device status data and user behavior data separately, and fuses them through a spatiotemporal attention mechanism to generate a three-dimensional behavior baseline model; The federated learning analysis cluster consists of edge computing units deployed on each industrial control node. It uses differential privacy technology to encrypt local behavior features, implements cross-domain model aggregation through parameter servers, and outputs a global abnormal behavior map. The attack chain prediction module integrates the Hidden Markov Model (HMM) and the Graph Neural Network (GNN) to predict potential attack paths based on real-time behavioral deviations and generate threat intelligence including attack stage identification. Adaptive protection policy executor dynamically reconstructs access control rules based on the software-defined security (SDS) architecture, supports millisecond-level delivery and rollback of protection policies, and includes a triple protection mechanism of traffic rate limiting, port isolation, and instruction whitelisting. The model evolution feedback loop optimizes the federated learning aggregation weights through reinforcement learning and adopts adversarial sample generation technology to enhance the robustness of the baseline model against zero-day attacks.

2. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The multi-source data fusion acquisition module is connected to the industrial control network in parallel through the industrial bus and the mirror port, and its output end is connected to the heterogeneous data input interface of the dynamic behavior modeling engine; The dynamic behavior modeling engine receives real-time data streams from the multi-source data fusion acquisition module. Its baseline model output is connected to the local model upload interface of the federated learning analysis cluster via the OPC UA protocol, and provides behavior deviation indicators to the attack chain prediction module. Each edge computing unit in the federated learning analysis cluster is connected to the central parameter server via the time-sensitive network (TSN). Its global anomaly graph generation end is connected to the threat intelligence fusion layer of the attack chain prediction module via a RESTful API. The attack chain prediction module receives real-time deviation data from the dynamic behavior modeling engine and the global anomaly map from the federated learning analysis cluster. Its attack path prediction results are pushed to the policy decision engine of the adaptive protection policy executor via the MQTT message queue. The adaptive protection policy executor includes an OpenFlow interface directly connected to the control plane switch and an execution result feedback channel, including: The protection policy delivery interface is synchronized in real time with the SDN controller in the industrial control network; The policy execution effect data is transmitted back to the model evolution feedback loop via the data plane collection agent; The model evolution feedback loop establishes a two-way data channel with the weight adjustment interface of the dynamic behavior modeling engine and the aggregation algorithm update interface of the federated learning analysis cluster through a cross-layer feedback bus, forming a closed-loop optimization mechanism.

3. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The multi-source data fusion acquisition module includes: The physical interface security protection unit uses a Y-shaped metal limit bar and piezoelectric sensor composite structure. When unauthorized plug-in or plug-out operations are detected, the physical locking mechanism and digital certificate revocation are triggered simultaneously. The protocol deep parsing unit supports instruction-level reorganization of industrial control protocols transmitted on non-standard ports, and identifies abnormal payloads disguised as legitimate protocols through syntax tree comparison.

4. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The dynamic behavior modeling engine includes: The device profile generation unit builds differentiated behavioral evaluation indicators based on device type PLC / RTU / HMI, with the PLC controller adding a register write frequency weighting factor. The user behavior baseline library establishes a multi-level operation sequence Markov chain based on role permissions, and implements double behavior verification for high-risk operations.

5. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The federated learning analysis cluster uses: Gradient obfuscation mechanism, which injects Gaussian noise during local model training to ensure that the original data characteristics cannot be restored during parameter updates; Dynamic participating node selection algorithm dynamically adjusts federated learning participating nodes based on device online status, computing resource margin, and security posture score.

6. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The attack chain prediction module implements: Multi-stage attack correlation analysis: causal reasoning between device abnormalities and network behavior, generating attack stage assessment reports mapped to the MITRE ATT&CK framework; The risk quantification decision matrix uses the analytic hierarchy process (AHP) to calculate the threat value of each attack path: where w i is the attack phase weight, S i is the current behavior deviation, k is the situation sensitivity coefficient, and S0 is the baseline deviation threshold.

7. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The adaptive protection strategy executor includes: The digital twin verification sandbox performs virtual execution of suspicious control instructions and confirms attack behavior by comparing the state deviation value of the actual device and the digital twin by Δ>15%; The policy conflict resolver automatically selects the optimal execution plan based on business continuity priority when multiple protection policies are mutually exclusive.

8. The industrial control network security and business security assurance system based on behavior analysis according to claim 1 is characterized in that: The model evolution feedback loop implements: Adversarial example evolution mechanism, using Wasserstein GAN to generate adversarial examples that conform to the physical constraints of industrial control, enhancing the model's ability to identify covert attacks; The incremental learning scheduler automatically triggers local model retraining based on device firmware upgrade records to maintain version consistency between the behavioral baseline model and the physical device.

9. The industrial control network security and business security assurance system based on behavior analysis according to claim 3 is characterized in that: The physical interface security protection unit integrates: A multimodal authentication module that requires simultaneous verification of the digital certificate and physical key during physical connection, activating a self-destruct fuse circuit if authentication fails; The electromagnetic fingerprint collection unit establishes a unique identification library for the device hardware by monitoring the electromagnetic radiation characteristics when the interface is connected.

10. The industrial control network security and business security assurance system based on behavior analysis according to claim 4 is characterized in that: The user behavior baseline library implements: Two-factor behavioral verification, coupling user biometrics with operation timing patterns for verification; Context-aware correction automatically adjusts the allowed operation time window according to changes in production plans, and implements the four-eye principle for approval of high-risk operations in unplanned periods.

Citation Information

Patent Citations

  • An industrial host network security operation and maintenance monitoring system

    CN119766482A

  • Information security risk assessment whole-process management system

    CN119939591A

  • Network security situation adaptive active defense system and method

    WO2023077617A1

Cited By

  • Repair method of server and electronic equipment

    CN120743613A

  • Software control management method and system based on intelligent algorithm and storage medium

    CN121009513A

  • Network attack path tracking method and system based on three-domain communication event structure

    CN121037104A

  • Power grid malicious flow detection method and system based on adaptive integration

    CN121309205A

  • A power grid malicious traffic detection method and system based on adaptive integration

    CN121309205B