Industrial production process APT attack detection method and system based on knowledge graph
By constructing a three-dimensional semantic knowledge graph of the industrial production process and combining it with graph embedding and graph convolutional networks, we have solved the cross-protocol camouflage and multi-hop penetration problems of APT attacks in industrial networks, achieved real-time detection and tracing of complex attack behaviors, and improved the security and defense capabilities of industrial systems.
Patent Information
- Application Number
- CN202510816588.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-09-19
AI Technical Summary
Existing industrial network attack detection technologies are unable to effectively deal with the cross-protocol masquerade and multi-hop penetration characteristics of APT attacks, and their ability to fuse multi-source heterogeneous data is insufficient, resulting in high delays in attack behavior identification and low tracing success rates, making it difficult to achieve active defense.
Build a three-dimensional semantic dynamic knowledge graph of device-protocol-data flow, combine graph embedding technology and graph convolutional network to achieve real-time detection and tracing of hidden attack chains, identify known attack chains through multi-hop matching, integrate temporal graph convolutional network and attention mechanism to detect unknown abnormal behaviors, and perform data fusion based on the topological relationship of the knowledge graph.
It significantly improves the cross-domain correlation analysis capability of covert APT attacks, realizes real-time detection and risk quantification of complex attack behaviors, shortens the response time of security incidents, and enhances the active defense capability of industrial systems.
Smart Images

Figure CN120675763A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the interdisciplinary field of industrial Internet security and artificial intelligence, and in particular to a method and system for detecting APT attacks in industrial production processes based on a knowledge graph. Background Art
[0002] Industrial control systems, as the core of modern industrial production processes, carry the real-time monitoring and control functions of critical infrastructure. With the deep integration of the Industrial Internet and physical systems, industrial production environments are characterized by heterogeneous equipment, diverse protocols, and complex data flows, forming a highly dynamic, tightly coupled digital production network. However, while this network improves production efficiency, it also faces severe challenges from highly concealed and long-latent advanced persistent threats (APT attacks). These attacks often achieve lateral penetration by disguising legitimate process instructions, resulting in significant risks of missed and false positives in traditional detection methods based on feature rules or traffic thresholds.
[0003] However, existing industrial network attack detection technologies mainly rely on deep protocol analysis and abnormal traffic statistics, which makes it difficult to effectively deal with the cross-protocol camouflage and multi-hop penetration characteristics of APT attacks. Specifically, the current methods have three technical defects: First, the process logic associations between industrial equipment entities have not been structured and modeled, resulting in a lack of multi-dimensional semantic support for attack chain reasoning; second, attack behavior feature extraction is mostly limited to single-point data packet analysis, which cannot capture long-term attack paths across devices and protocols; third, the detection model update mechanism lags behind the dynamic adjustment of the production process, and it is difficult to adapt to the changes in the attack surface brought about by the reconstruction of the process. For example, the anomaly detection algorithm based on supervised learning needs to rely on a predefined attack feature library, and its generalization ability for new covert attacks is insufficient; and although the static knowledge graph can express the topological relationship between devices, it cannot associate protocol interactions with data flow timing characteristics in real time, resulting in a logical gap in attack intent reasoning.
[0004] In addition, existing technologies lack the ability to integrate multi-source heterogeneous data in industrial control systems. The correlation analysis of equipment status, control instructions, and data flow often adopts an independent processing mode, making it difficult to collaboratively discover abnormal characteristics of attack behaviors in protocol compliance verification, process logic compliance verification, data integrity auditing and other links. However, the system using single-dimensional detection technology has a high average recognition delay for APT attacks and a low attack tracing success rate, which seriously restricts the active defense capability of industrial production safety. At this stage, there is a need for an industrial production process APT attack detection method and system based on knowledge graph. Summary of the Invention
[0005] In order to solve the problem of insufficient detection and tracing capabilities of covert APT attacks in traditional industrial production processes, the present invention provides an industrial production process APT attack detection method and system based on knowledge graph. The present invention constructs a three-dimensional semantic dynamic knowledge graph of equipment-protocol-data flow, integrates graph embedding technology and graph convolutional network, and realizes real-time detection and tracing of covert attack chains.
[0006] In the first aspect, the present invention provides a method for detecting APT attacks in industrial production processes based on a knowledge graph, which adopts the following technical solutions:
[0007] A knowledge graph-based method for detecting APT attacks in industrial production processes, including:
[0008] Acquire industrial production data and pre-process the acquired industrial production data;
[0009] The pre-processed industrial production data is used as input to dynamically construct a knowledge graph, including building a three-dimensional semantic network of equipment, protocol, and data flow, and generating a control flow graph by parsing SCADA instructions;
[0010] Reasoning about known attack patterns based on knowledge graphs, including identifying known attack chains using multi-hop matching embedded in graphs and generating multi-dimensional attack confidence indicators;
[0011] The fusion of a temporal graph convolutional network and an attention mechanism detects unknown abnormal behaviors. This includes updating node states layer by layer through a temporal graph convolutional network and introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes.
[0012] Data fusion based on the topological relationship of the knowledge graph, including evidence fusion of the matching results of attack pattern reasoning and the deviation indicators of abnormal behavior detection;
[0013] Based on the data fusion results, the attack entry node, associated entities and propagation path are located.
[0014] Furthermore, the acquired industrial production data is preprocessed, including segmenting the original industrial production data through a sliding time window for data with different sampling rates, using a dynamic time warping algorithm to align the heterogeneous time series data within each time window, and finally converting the aligned time series data into a unified feature matrix. The dynamic time warping algorithm formula is:
[0015]
[0016] Among them, x i It is represented as the time series data value of a certain type of sensor at the i-th sampling point in the industrial production process, y jIt is represented as the time series data value of another type of sensor at the jth sampling point, and π is represented as the alignment path between the X and Y elements, that is, the optimal path with the minimum total distance.
[0017] Furthermore, the pre-processed industrial production data is used as input to dynamically construct a knowledge graph, including constructing a three-dimensional semantic network of equipment, protocol, and data flow, defining the class structure, protocol attributes, and control logic relationships between entities of industrial equipment through the OWL language, and obtaining a four-tuple ontology model O=(E, P, R, C) including an entity set, a relationship set, a rule set, and a coverage index. The entity set E includes at least industrial equipment entities and protocol attribute definitions, the relationship set P uses RDF triples to model the control logic relationships and data flow dependencies between entities, and the rule set R includes process constraint rules. The coverage index P represents the entity relationship coverage calculated as:
[0018]
[0019] Among them, E actual is the actual device set, E model To model the covering entity, P actual is the actual entity relationship set, P model Represents a collection of entity relationships that model coverage.
[0020] Furthermore, the dynamic construction of the knowledge graph using the preprocessed industrial production data as input also includes generating a control flow graph by parsing SCADA instructions, and updating the knowledge graph topology when new equipment access or protocol session abnormalities are detected. The protocol session abnormalities include at least illegal Modbus function code calls, OPC UA node ID format abnormalities, and communication frequency deviations from the baseline. Finally, the preprocessed industrial production data and historical fault logs are used to generate initial embedding vectors of entities and relationships through graph convolutional network training to achieve incremental initialization of the knowledge graph.
[0021] Furthermore, the reasoning of known attack patterns based on the knowledge graph includes mapping industrial equipment entities and attack behaviors to the relational space using graph embedding technology, triggering multi-hop reasoning through the distance measurement of the graph space, and realizing the identification of known attack chains. The graph embedding technology uses the TransR algorithm to map entities and relationships to a multi-dimensional independent semantic space, linearly transforms each entity in the entity space to the relational space through the relation-specific projection matrix, and completes relational reasoning based on the relational space using vector translation operations. The translation operation formula is:
[0022] h r +r≈t r ,
[0023] Among them, h rrepresents the head entity projection vector, r represents the embedding vector of the relationship, representing the translation operation in the relationship space, t r Represented as the tail entity projection vector.
[0024] Furthermore, the multi-hop matching using graph embedding to identify known attack chains includes calculating the cosine similarity between the real-time session vector and the attack pattern feature vector in the historical attack pattern library, dynamically adjusting the matching threshold based on the device type and historical attack logs, and using a hierarchical threshold as the determination mechanism for the matching threshold. When the similarity exceeds the threshold, it is marked as a potential attack. The calculation formula for the cosine similarity is:
[0025]
[0026] Among them, V log It is represented as a vectorized feature that may represent the traffic log, V attack A feature vector representing a known attack pattern.
[0027] Furthermore, the fusion of the time-series graph convolutional network and the attention mechanism detects unknown abnormal behaviors, including updating the node status layer by layer through the time-series graph convolutional network, superimposing the dynamic time-series data of the industrial control system and the knowledge graph ontology embedding dimension, performing graph convolution operations based on the message passing framework, and finally introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes. The message passing formula is:
[0028]
[0029] in, represents the hidden state of node i in the l-1 layer and time window t, represents the dynamic edge feature, φ represents the message generation function, Represents knowledge graph ontology embedding.
[0030] Furthermore, the data fusion based on the topological relationship of the knowledge graph includes evidence fusion of the confidence index of the known attack node and the deviation index of the abnormal behavior detection, performing multi-node message calculation through the graph neural network message passing mechanism, aggregating neighbor messages through multi-head attention based on the fused evidence, dynamically assigning node weights and backtracing the attack propagation path, and calculating the path confidence by multiplying the node states. The message calculation formula is:
[0031]
[0032] Among them, φ1 represents the fusion function, Expressed as the known attack confidence of node i, It is represented as the unknown abnormal deviation index of node j, r ijIt is represented as the control link strength between node i and node j.
[0033] Furthermore, the attack entry nodes, associated entities, and propagation paths are located based on the data fusion results, including taking nodes with known attack confidence higher than a preset threshold as candidate attack entry points, combining them with nodes with unknown abnormal deviations exceeding a dynamic threshold, and filtering strongly associated entities through the "control dependency" and "data flow" relationship edges in the knowledge graph to form an attack entry set. Finally, the node status is updated and the attack path is generated:
[0034]
[0035] Among them, ψ is the GRU unit, ΔT i is the timing deviation, represents the state value of node i in the l-1th layer, Represents the neighborhood aggregated message of node i in the l-th layer reasoning.
[0036] The second aspect is a knowledge graph-based industrial production process APT attack detection system, including:
[0037] The data acquisition module is configured to: acquire industrial production data and pre-process the acquired industrial production data;
[0038] The knowledge graph module is configured to: take pre-processed industrial production data as input to dynamically construct a knowledge graph, including building a three-dimensional semantic network of equipment, protocol, and data flow, and generate a control flow graph by parsing SCADA instructions;
[0039] The attack pattern reasoning module is configured to: reason about known attack patterns based on the knowledge graph, including identifying known attack chains using multi-hop matching of graph embeddings and generating multi-dimensional attack confidence indicators;
[0040] The abnormal behavior detection module is configured to: integrate a temporal graph convolutional network with an attention mechanism to detect unknown abnormal behaviors. This includes updating node states layer by layer through a temporal graph convolutional network and introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes.
[0041] The attack tracing module is configured to: perform data fusion based on the topological relationships of the knowledge graph, including evidence fusion of the matching results of attack pattern reasoning and the deviation indicators of abnormal behavior detection;
[0042] The output module is configured to locate the attack entry node, associated entities and propagation path based on the data fusion results.
[0043] In summary, the present invention has the following beneficial technical effects:
[0044] 1. This invention achieves structured modeling and dynamic association of all-factor data of industrial production by constructing a three-dimensional semantic network of equipment, protocol and data flow, breaking through the limitations of traditional single-dimensional detection and significantly improving the cross-domain correlation analysis capability of covert APT attacks.
[0045] 2. The multi-hop matching mechanism of this invention, based on graph embedding technology, can quickly identify known attack chain patterns. Combined with dynamic threshold adjustment and multi-dimensional attack scoring, it can achieve real-time detection and risk quantification of complex attack behaviors such as cross-protocol masquerade and long-term penetration.
[0046] 3. This invention integrates the temporal graph convolutional network and the attention mechanism to effectively capture the spatiotemporal dependency characteristics of industrial control data. Through dynamic time windows and weight distribution of high-risk nodes, it improves the generalization detection capability of new attacks without historical characteristics.
[0047] 4. This invention relies on the evidence fusion and triple reasoning of the topological relationship of the knowledge graph to accurately locate the attack entry node and propagation path, realize the automation of the entire process from anomaly detection to attack chain backtracing, and greatly shorten the response time of security incidents.
[0048] 5. The present invention uses a dynamic update mechanism of the knowledge graph generated by SCADA instruction parsing and control flow graph generation to respond in real time to changes in scenarios such as industrial network equipment access and protocol changes, ensuring continuous adaptation of detection models and production processes.
[0049] 6. The present invention forms a complete technical closed loop of "data collection-knowledge modeling-attack detection-tracing response-model optimization", providing an integrated solution from attack identification to defense strategy execution, and enhancing the active defense capability of industrial systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 This is an architectural diagram of an industrial production process APT attack detection method based on a knowledge graph in Example 1 of the present invention.
[0051] Figure 2 This is a knowledge graph modeling flowchart of an industrial production process APT attack detection method based on a knowledge graph in Example 1 of the present invention.
[0052] Figure 3 This is an attack pattern reasoning diagram of an industrial production process APT attack detection method based on a knowledge graph in Example 1 of the present invention. DETAILED DESCRIPTION
[0053] The present invention will be further described in detail below with reference to the accompanying drawings.
[0054] Example 1
[0055] Reference Figure 1, a method for detecting APT attacks in industrial production processes based on a knowledge graph in this embodiment includes:
[0056] Acquire industrial production data and pre-process the acquired industrial production data;
[0057] The pre-processed industrial production data is used as input to dynamically construct a knowledge graph, including building a three-dimensional semantic network of equipment, protocol, and data flow, and generating a control flow graph by parsing SCADA instructions;
[0058] Reasoning about known attack patterns based on knowledge graphs, including identifying known attack chains using multi-hop matching embedded in graphs and generating multi-dimensional attack confidence indicators;
[0059] The fusion of a temporal graph convolutional network and an attention mechanism detects unknown abnormal behaviors. This includes updating node states layer by layer through a temporal graph convolutional network and introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes.
[0060] Data fusion based on the topological relationship of the knowledge graph, including evidence fusion of the matching results of attack pattern reasoning and the deviation indicators of abnormal behavior detection;
[0061] Based on the data fusion results, the attack entry node, associated entities and propagation path are located.
[0062] Specifically, a method for detecting APT attacks in industrial production processes based on knowledge graphs includes the following steps:
[0063] Step 1: Dynamic construction of knowledge graph;
[0064] like Figure 1 、 Figure 2 As shown in the figure, first, the class structure and protocol attributes (such as Modbus function code and OPC UA node ID) of industrial equipment entities (such as PLC and DCS) are defined by OWL language to model the industrial production process ontology. The industrial equipment ontology model adopts a four-tuple structure:
[0065] Ontology model O = (E, P, R, C),
[0066] Among them, E represents the entity set, which defines the device entity class structure and subclass relationships. Describe, for example By using OWL language to constrain protocol attributes (such as Modbus function code range 1≤f c≤255); P represents a relation set. The control logic relation is modeled as an RDF triple P = {(s, p, o) | s, o∈E, p∈{control, data flow, ...}}, such as (PLC-A, control, valve-B); R represents a rule set. The process constraint is expressed in first-order logic, such as the temperature alarm rule:
[0067]
[0068] It is expressed as a first-order logic rule that triggers an alarm when the reactor temperature exceeds 150°C.
[0069] C represents the coverage index, and the entity relationship coverage is calculated as:
[0070]
[0071] Among them, E actual is the actual device set, E model To model the covering entity, P actual is the actual entity relationship set, P model Represents a collection of entity relationships that model coverage.
[0072] In the industrial production data preprocessing phase, multi-source data from the industrial field is collected in real time through the OPC UA protocol. This data covers the status of equipment such as PLCs and DCSs, protocol interaction data such as Modbus / OPC UA, and sensor process parameters. A dynamic time warping algorithm is used to find the optimal path π and minimize the sum of the Euclidean distances between sequences X and Y at different sampling rates. This algorithm then performs time alignment on sensor data at different sampling rates (e.g., 1 Hz for temperature sensors and 10 Hz for pressure sensors). The calculation formula is:
[0073]
[0074] Among them, x i It is represented as the time series data value of a certain type of sensor at the i-th sampling point in the industrial production process, y j It is represented as the time series data value of another type of sensor at the jth sampling point, and π is represented as the alignment path between the X and Y elements, that is, the optimal path with the minimum total distance.
[0075] Convert the aligned time series data into a three-dimensional feature matrix, that is, generate a feature matrix with a unified time base:
[0076]
[0077] Among them, m is the number of device nodes, n is the time window length, and d is the feature dimension. A standardized multidimensional feature data set, such as a matrix containing 100 devices, a 10-second window, and 50-dimensional features, provides a basis for knowledge graph modeling.
[0078] The specific implementation process is as follows: First, for sensor data with different sampling rates (such as a pressure sensor sampling at a high frequency of 10Hz and a temperature transmitter outputting at a low frequency of 1Hz), the raw data is segmented using a sliding time window (the default window width is 10 seconds) to form a collection of local time series segments. Within each time window, an improved DTW algorithm is used to align the heterogeneous time series data. The aligned data stream ultimately generates a unified multidimensional feature matrix with a time base aligned to the master clock pulse signal of the SCADA system (with an error of less than 1ms). Low-latency data transmission to downstream analysis modules is achieved via the OPC UA Pub / Sub mechanism.
[0079] Then, the existing normal production operation data and fault logs are processed using industrial production data preprocessing to obtain a labeled multi-dimensional feature matrix. The graph neural network is trained using graph convolution to generate initial entity and relationship embedding vectors. Finally, a control flow graph (CFG) is generated through SCADA instruction parsing to identify data flow dependencies between devices. When new device access or protocol session anomalies are detected, the knowledge graph is updated.
[0080] Step 2: Identify known attacks through multi-hop matching in the graph embedding space;
[0081] like Figure 3 As shown in the figure, this step involves knowledge graph representation learning, graph neural network reasoning, and industrial network attack pattern recognition. It is suitable for the rapid positioning and risk assessment of known attack chains in industrial control systems. For the knowledge graph generated in step 1, the TransR algorithm is used to map entities and relationships to 128-dimensional independent semantic spaces for modeling. The TransR algorithm framework includes entity space, relationship space, and projection transformation. The entity space maps entities such as industrial equipment (such as PLCs, sensors) and attack behaviors (such as "abnormal communication" and "data tampering") to a 128-dimensional vector space. The relationship space corresponds to an independent 128-dimensional vector space R for each relationship (such as "control" and "attack"). 128 and the relation-specific projection matrix M r ∈R 128 ×128 , the projection transformation is the entity embedding vector h,t∈R 128 , through matrix operation h r =hM r and t r =tM r Project it into the relational space, where relational reasoning is achieved through vector addition, and the objective function is:
[0082]
[0083] Where S is the set of positive sample triplets (such as (PLC, abnormal communication, sensor)), S' is the set of negative sample triplets, γ is the interval hyperparameter, which is 0.5, [x] + =max(0,x) is the hinge loss function,
[0084] Each entity in the entity space (such as industrial equipment PLC, sensor) is represented by a relation-specific projection matrix (for example, M corresponding to the attack behavior "abnormal communication"). r ) is linearly transformed into the relational space, and the relational reasoning is completed in this space using vector translation operation. The translation operation formula is:
[0085] h r +r≈t r ,
[0086] where h, is the embedding vector of the head and tail entities in the entity space, is the embedding vector of relation r, representing the translation operation in the relation space, h r Represents the head entity projection vector, representing the translation operation in the relation space, t r This mechanism allows for dynamic semantic expression of the same entity in different relationships (for example, the projection results of a PLC device in the "protocol violation" and "data tampering" relationships are different), effectively modeling complex relationships (such as many-to-many dependencies in industrial attack scenarios).
[0087] Then, the cosine similarity between the session vector and the attack pattern library is calculated. When S > the threshold, an abnormal session alarm is triggered. The formula for calculating cosine similarity is:
[0088]
[0089] Among them, V log represents the vectorized features that may represent traffic logs, V attack is the feature vector of the known attack pattern.
[0090] The dynamic similarity threshold judgment mechanism uses a hierarchical threshold and dynamically adjusts the matching threshold based on the device type (e.g., PLC high-risk device threshold = 0.75, sensor = 0.85) and historical attack logs. When the similarity between the session vector and the attack pattern library exceeds the threshold, it is marked as a potential attack.
[0091] SPARQL attack chain query automatically generates SPARQL query statements based on ATT&CK ICS attack chain patterns (such as T0865 lateral movement), supporting 3-5 hop attack path retrieval.
[0092] The multi-dimensional attack scoring model uses multi-dimensional feature fusion to integrate protocol compliance (weighted 30%, such as illegal Modbus function code calls), device abnormal status (weighted 50%, such as sudden increase in CPU load), and data flow timing deviation (weighted 20%, such as instruction cycle deviation from the baseline). The weighted sum is used to generate an attack confidence index (0-1). When it exceeds 0.6, an alarm is triggered and the attack chain evidence is associated.
[0093] Step 3: Integrate the temporal graph convolutional network and attention mechanism to detect unknown abnormal behaviors;
[0094] The multidimensional spatiotemporal matrix preprocessed in step 1 Embedded with knowledge graph ontology Splicing is done to form a spatiotemporal input tensor. Based on the Message-Aggregation-Update framework in the message passing formula, the dynamic time series data of the industrial control system is superimposed with the knowledge graph ontology embedding dimension to perform graph convolution message passing. The message calculation formula is:
[0095]
[0096] in, represents the hidden state of node i (such as PLC controller) at the l-1th layer and time window t (encoding historical control instruction sequence features), represents the dynamic edge features (such as the Modbus / TCP communication frequency and protocol type between the PLC and the actuator in the window t), φ represents the message generation function (the gated linear unit is often used in industrial scenarios: φ(x) = Wx + b, are learnable parameters), Represent knowledge graph ontology embedding (such as device type encoding, vectorized representation of protocol compliance labels).
[0097] The neighborhood aggregation formula is:
[0098]
[0099] in, represents the set of neighbors of node i (such as pressure sensors and valve actuators directly connected to the PLC in the control link), represents the industrial customized aggregation operator (weighted maximum pooling is used for high-risk equipment, and mean pooling is used for ordinary equipment). Represents the dynamic attention weight (calculated by the device risk level and real-time load, such as the weight × 2 when the CPU load is > 80%).
[0100] The state update formula is:
[0101]
[0102] Where ψ represents the state update function (GRU units are commonly used in industrial scenarios, introducing process timing constraints), Indicates the timing deviation characteristic (the offset between the current control period and the baseline).
[0103] A multi-head attention mechanism is introduced to dynamically assign abnormal sensitivity weights to high-risk nodes (such as reactor pressure controllers). The formula is:
[0104]
[0105] Among them, H is the node feature matrix, which contains the state vectors of N industrial equipment nodes. is the query matrix of the kth attention head, which is used to map node features to the query space. Represented as the key matrix of the k-th attention head, used to map node features to the key space, It is represented as the value matrix of the kth attention head, which is used to map node features to the value space. Different heads focus on different risk dimensions: head 1 (k=1) focuses on process criticality (such as increasing the weight of pressure vessels), head 2 (k=2) analyzes historical attack frequency (frequently attacked PLCs are given increased weight), and head 3 (k=3) monitors real-time threat indicators (dynamically adjust weights when CPU / memory increases suddenly); β k is the dynamic weight coefficient, d k Dimension scaling factor: prevents the dot product value from being too large and causing the gradient to disappear, usually d k =d / K (K is the number of attention heads).
[0106] And through historical operation data training, an adaptive dynamic threshold is generated. When the real-time deviation exceeds the threshold, a graded alarm (early warning / serious alarm) is triggered. The dynamic threshold adjustment is expressed as:
[0107]
[0108] Among them, θ0 is the basic threshold, α is the total frequency adjustment coefficient, β is the load adjustment coefficient, AttackRate i is the ratio of the number of attacks on device i in the past time period (such as 24 hours) to the total number of detections, is the real-time load percentage of device i at time t, where the warning is expressed as Serious warnings are indicated by
[0109] Step 4: Locate attack entry nodes, associated entities, and propagation paths based on multi-module data.
[0110] This step involves knowledge graph reasoning, time series data analysis, and industrial control network attack path backtracing, and is suitable for locating the source and analyzing the propagation path of APT attacks in industrial production processes.
[0111] First, the known attack matching results output by the attack pattern reasoning module are integrated, that is, the attack confidence calculated based on the TransR algorithm Combined with the unknown abnormal deviation index output by the abnormal behavior detection module, Based on the topological relationship of the knowledge graph, triple reasoning is performed to perform message calculation on known attack nodes (such as PLCs with malicious code implanted) and unknown abnormal nodes (such as high-frequency communication sensors):
[0112]
[0113] Among them, φ1 represents the fusion function, Expressed as the known attack confidence of node i, It is represented as the unknown abnormal deviation index of node j, r ij It is represented as the control link strength between node i and node j.
[0114] Then, multi-head attention is used to aggregate neighbor messages and dynamically assign node weights:
[0115]
[0116] Among them, α ij Dynamically calculated based on the device risk level (high-risk node weight × 1.5) and real-time load (CPU > 80% × 2);
[0117] Finally, update the node status and generate the attack path:
[0118]
[0119] Among them, ψ is the GRU unit, ΔT i is the timing deviation, represents the state value of node i in the l-1th layer, Indicates the neighborhood aggregation message of node i in the l-th layer reasoning. When , the path is generated by backtracking along the "control dependency" edge (such as PLC→sensor→valve), and the path confidence is determined by calculate.
[0120] This step integrates multi-source data with the topological relationships of the knowledge graph to achieve full-link traceability of APT attacks. It specifically includes three core steps: attack entry location, associated entity screening, and propagation path generation. Its working principle is as follows:
[0121] The attack entry node is located using the attack confidence output by the attack pattern inference module (such as the node risk value calculated based on the TransR algorithm, ranging from 0 to 1). When the confidence of a node exceeds a preset threshold (such as 0.75), it is determined to be a candidate attack entry (for example, a PLC is marked because it matches a known malicious code implantation pattern). Unknown abnormal evidence: through the deviation indicator of the abnormal behavior detection module (such as the degree to which real-time data calculated by the time series graph convolutional network deviates from the baseline), when the node deviation exceeds a dynamic threshold (such as 1.2 times the historical baseline), it is included in the suspicious node set (for example, a sensor is marked due to high-frequency abnormal communication).
[0122] Based on the relationship edges such as "control dependency" and "data flow" in the knowledge graph, the association strength between candidate nodes and suspicious nodes is calculated. For example: if there is a "control" relationship between the PLC (candidate entry) and the sensor (suspicious node), and the historical communication frequency is higher than the average, it is judged to be a strong association. Through triple reasoning (subject-relationship-object), nodes that meet both "high attack confidence" and "strong topological association" are screened out to form the final attack entry set.
[0123] For each pair of nodes (attack entry node i, suspicious node j), the associated entity filtering calculates the message value through the fusion function φ1 Dynamically adjust the aggregation weight α of neighbor nodes according to the device risk level and real-time load ij , by weighted aggregation of neighbor messages Generate comprehensive risk characteristics of node i.
[0124] Propagation path generation uses GRU (Gated Recurrent Unit) to integrate historical states With the current aggregate message And superimpose the timing deviation characteristic ΔT i , the GRU mechanism retains the temporal dependency of attack evidence (such as the temporal correlation of multi-stage attacks), the temporal deviation ΔT i Enhance the sensitivity to hidden time anomalies, when the node status When a node is found, it is determined to be a key node in the attack chain and path backtracking is triggered. Starting from the attack entry, the related entities within 3-5 hops are recursively retrieved along the "control dependency" and "data flow" relationship edges (which is consistent with the typical propagation depth of industrial attacks). The path where high-risk equipment is located (such as reactor controller → valve → production line) is given priority. The path confidence is calculated by multiplying the node status values. When the path confidence exceeds 0.8 and the high-confidence node cannot be further expanded, the backtracking is terminated to generate a complete attack chain.
[0125] Example 2
[0126] This embodiment differs from Example 1 in that it provides an industrial production process APT attack detection system based on a knowledge graph, including:
[0127] The data acquisition module is configured to: acquire industrial production data and pre-process the acquired industrial production data;
[0128] The knowledge graph module is configured to: take pre-processed industrial production data as input to dynamically construct a knowledge graph, including building a three-dimensional semantic network of equipment, protocol, and data flow, and generate a control flow graph by parsing SCADA instructions;
[0129] The attack pattern reasoning module is configured to: reason about known attack patterns based on the knowledge graph, including identifying known attack chains using multi-hop matching of graph embeddings and generating multi-dimensional attack confidence indicators;
[0130] The abnormal behavior detection module is configured to: integrate a temporal graph convolutional network with an attention mechanism to detect unknown abnormal behaviors. This includes updating node states layer by layer through a temporal graph convolutional network and introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes.
[0131] The attack tracing module is configured to: perform data fusion based on the topological relationships of the knowledge graph, including evidence fusion of the matching results of attack pattern reasoning and the deviation indicators of abnormal behavior detection;
[0132] The output module is configured to locate the attack entry node, associated entities and propagation path based on the data fusion results.
[0133] The above are all preferred embodiments of the present invention, and are not intended to limit the scope of protection of the present invention. Therefore, any equivalent changes made based on the structure, shape, and principle of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for detecting APT attacks in industrial production processes based on knowledge graphs, characterized in that: include: Acquire industrial production data and pre-process the acquired industrial production data; The pre-processed industrial production data is used as input to dynamically construct a knowledge graph, including building a three-dimensional semantic network of equipment, protocol, and data flow, and generating a control flow graph by parsing SCADA instructions; Reasoning about known attack patterns based on knowledge graphs, including identifying known attack chains using multi-hop matching embedded in graphs and generating multi-dimensional attack confidence indicators; The fusion of a temporal graph convolutional network and an attention mechanism detects unknown abnormal behaviors. This includes updating node states layer by layer through a temporal graph convolutional network and introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes. Data fusion based on the topological relationship of the knowledge graph, including evidence fusion of the matching results of attack pattern reasoning and the deviation indicators of abnormal behavior detection; Based on the data fusion results, the attack entry node, associated entities and propagation path are located.
2. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The obtained industrial production data is preprocessed, including segmenting the original industrial production data through a sliding time window for data with different sampling rates, using a dynamic time warping algorithm to align the heterogeneous time series data within each time window, and finally converting the aligned time series data into a unified feature matrix. The dynamic time warping algorithm formula is: Among them, x i It is represented as the time series data value of a certain type of sensor at the i-th sampling point in the industrial production process, y j It is represented as the time series data value of another type of sensor at the jth sampling point, and π is represented as the alignment path between the X and Y elements, that is, the optimal path with the minimum total distance.
3. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The pre-processed industrial production data is used as input to dynamically construct a knowledge graph, including constructing a three-dimensional semantic network of equipment, protocol, and data flow. The class structure, protocol attributes, and control logic relationships between entities of industrial equipment are defined using the OWL language to obtain a four-tuple ontology model O=(E, P, R, C) including an entity set, a relationship set, a rule set, and a coverage index. The entity set E includes at least industrial equipment entities and protocol attribute definitions. The relationship set P uses RDF triples to model the control logic relationships and data flow dependencies between entities. The rule set R includes process constraint rules. The coverage index P represents the entity relationship coverage calculated as: Among them, E actual is the actual device set, E model To model the covering entity, P actual is the actual entity relationship set, P model Represents a collection of entity relationships that model coverage.
4. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 3 is characterized in that: The method uses preprocessed industrial production data as input to dynamically construct a knowledge graph, and also includes generating a control flow graph by parsing SCADA instructions. When new equipment access or protocol session abnormalities are detected, the knowledge graph topology is updated. The protocol session abnormalities include at least illegal Modbus function code calls, OPC UA node ID format abnormalities, and communication frequency deviations from the baseline. Finally, the preprocessed industrial production data and historical fault logs are used to generate initial embedding vectors of entities and relationships through graph convolutional network training to achieve incremental initialization of the knowledge graph.
5. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The reasoning of known attack patterns based on the knowledge graph includes mapping industrial equipment entities and attack behaviors to the relational space using graph embedding technology, triggering multi-hop reasoning through the distance measurement of the graph space, and realizing the identification of known attack chains. The graph embedding technology uses the TransR algorithm to map entities and relationships to a multi-dimensional independent semantic space, linearly transforms each entity in the entity space to the relational space through the relation-specific projection matrix, and completes relational reasoning based on the relational space using vector translation operations. The translation operation formula is: h r +r≈t r , Among them, h r represents the head entity projection vector, r represents the embedding vector of the relationship, representing the translation operation in the relationship space, t r Represented as the tail entity projection vector.
6. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The multi-hop matching method using graph embedding to identify known attack chains includes calculating the cosine similarity between the real-time session vector and the attack pattern feature vector in the historical attack pattern library, dynamically adjusting the matching threshold based on the device type and historical attack logs, and using a hierarchical threshold to determine the matching threshold. When the similarity exceeds the threshold, it is marked as a potential attack. The formula for calculating the cosine similarity is: Among them, V log It is represented as a vectorized feature that may represent the traffic log, V attack A feature vector representing a known attack pattern.
7. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The proposed method integrates the time-series graph convolutional network and the attention mechanism to detect unknown abnormal behaviors. It includes updating the node status layer by layer through the time-series graph convolutional network, superimposing the dynamic time-series data of the industrial control system and the knowledge graph ontology embedding dimension, performing graph convolution operations based on the message passing framework, and finally introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes. The message passing formula is: in, represents the hidden state of node i in the l-1 layer and time window t, represents the dynamic edge feature, φ represents the message generation function, Represents knowledge graph ontology embedding.
8. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The data fusion based on the topological relationship of the knowledge graph includes evidence fusion of the confidence index of the known attack node and the deviation index of the abnormal behavior detection, performing multi-node message calculation through the graph neural network message passing mechanism, aggregating neighbor messages through multi-head attention based on the fused evidence, dynamically assigning node weights and backtracking the attack propagation path, and calculating the path confidence by multiplying the node states. The message calculation formula is: Among them, φ1 represents the fusion function, Expressed as the known attack confidence of node i, It is represented as the unknown abnormal deviation index of node j, r ij It is represented as the control link strength between node i and node j.
9. The method for detecting APT attacks in industrial production processes based on knowledge graph according to claim 1, characterized in that: The method locates attack entry nodes, associated entities, and propagation paths based on data fusion results, including taking nodes with known attack confidence levels higher than a preset threshold as candidate attack entry points, combining them with nodes with unknown abnormal deviations exceeding a dynamic threshold, and filtering strongly associated entities through the "control dependency" and "data flow" relationship edges in the knowledge graph to form an attack entry set. Finally, the node status is updated and the attack path is generated: Among them, ψ is the GRU unit, ΔT i is the timing deviation, represents the state value of node i in the l-1th layer, Represents the neighborhood aggregated message of node i in the l-th layer reasoning.
10. A knowledge graph-based industrial production process APT attack detection system, executed according to the method of claim 1, characterized in that: include: The data acquisition module is configured to: acquire industrial production data and pre-process the acquired industrial production data; The knowledge graph module is configured to: take pre-processed industrial production data as input to dynamically construct a knowledge graph, including building a three-dimensional semantic network of equipment, protocol, and data flow, and generate a control flow graph by parsing SCADA instructions; The attack pattern reasoning module is configured to: reason about known attack patterns based on the knowledge graph, including identifying known attack chains using multi-hop matching of graph embeddings and generating multi-dimensional attack confidence indicators; The abnormal behavior detection module is configured to: integrate a temporal graph convolutional network with an attention mechanism to detect unknown abnormal behaviors. This includes updating node states layer by layer through a temporal graph convolutional network and introducing a multi-head attention mechanism to dynamically assign weights to high-risk nodes. The attack tracing module is configured to: perform data fusion based on the topological relationships of the knowledge graph, including evidence fusion of the matching results of attack pattern reasoning and the deviation indicators of abnormal behavior detection; The output module is configured to locate the attack entry node, associated entities and propagation path based on the data fusion results.
Citation Information
Cited By
Large-model-driven digital delivery factory digital human intelligent interaction method and system
CN120929180A
Large model driven digital delivery work digital human intelligent interaction method and system
CN120929180B
Network attack path tracking method and system based on three-domain communication event structure
CN121037104A
DDoS attack visual detection method based on multi-dimensional feature combinatorial analysis
CN121151137A
Heterogeneous device attack identification method and system based on heterogeneous device behavior map and adaptive feature learning
CN121283724A