Virtual-real fusion attack and defense drilling system and method for oil and gas production system, medium and equipment
Through the virtual-reality integrated attack and defense drill system, the on-site operating environment and attack conditions of the oil and gas production system are simulated, system anomalies are detected and protection strategies are invoked, which solves the security risk problems of the oil and gas production system and improves the emergency response capability and security protection capability.
Patent Information
- Application Number
- CN202510885439.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-19
AI Technical Summary
The complex network architecture of oil and gas production systems exposes them to security risks caused by information system failures. In particular, the coupling of information technology and operational technology exacerbates the spread of cyber attacks to physical production links, increases system vulnerability, and lacks effective emergency response capabilities.
A virtual-reality integrated attack and defense drill system for oil and gas production systems is provided, including a virtual-reality simulation module, a local attack module, and a security protection module. It simulates the on-site operating environment, monitors network risk areas, initiates attack commands, detects system anomalies, invokes protection strategies, and generates attack and defense drill reports.
The emergency response capability of the oil and gas production system has been improved, and different attacks and protection strategies have been simulated in a high-fidelity experimental environment, effectively ensuring the system's security and protection capabilities.
Smart Images

Figure CN120675778A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of oil and gas production industrial control system security, and in particular to a virtual-reality fusion attack and defense drill system, method, computer-readable storage medium and electronic device for an oil and gas production system. Background Art
[0002] With the advancement of industrial digitalization and intelligence, oil and gas production systems have become quintessential industrial cyber-physical systems (CPS). Modern oil and gas production systems integrate computing, communications, and control, forming a multi-layered, complex network architecture encompassing field equipment, control layers, and management layers. Field equipment uses sensors and actuators for data acquisition and control. The control layer, comprised of programmable logic controllers (PLCs) and distributed control systems (DCSs), processes data and sends control commands. The management layer connects to the control layer via industrial Ethernet, enabling integrated data analysis and decision-making. The intelligent and efficient nature of this system has driven the optimization of oil and gas production.
[0003] However, this convergence also presents unprecedented security risks. Complex network architectures mean that failures in information systems can trigger functional failures through cyber-physical interactions, leading to serious consequences such as oil and gas leaks and explosions. The unique nature of oil and gas production systems presents risks distinct from those of other information systems. In particular, the coupling of information technology (IT) and operational technology (OT) exacerbates the spread of cyberattacks to physical production processes, increasing system vulnerability. Summary of the Invention
[0004] The purpose of this application is to provide a virtual-reality integrated attack and defense drill system, method, computer-readable storage medium and electronic equipment for an oil and gas production system, which can effectively simulate the oil and gas production system and improve the emergency response capability of the oil and gas production system.
[0005] To solve the above technical problems, this application provides a virtual-reality integrated attack and defense drill system for oil and gas production systems. The specific technical solutions are as follows:
[0006] A virtual-reality simulation module is used to simulate the on-site operating environment of the oil and gas production system, maintain the communication and control relationship between the control center and the station equipment; and receive attack commands to simulate the physical impact of the station equipment of the oil and gas production system under attack conditions. The on-site operating environment includes at least the oil transfer station, gas gathering station, refining station, and gas transmission station, as well as the entire chain of production processes between them.
[0007] A local attack module, configured to monitor the network risk area of the oil and gas production system and invoke attack strategy instructions to initiate the attack instructions on the communication links or control nodes in the network risk area;
[0008] The security protection module is used to detect system anomalies of the station equipment in the simulation module, call the protection strategy matching the system anomaly to perform linkage protection, and generate an attack and defense drill report.
[0009] Optionally, the local attack module includes:
[0010] A monitoring submodule comprising a monitoring unit, a sniffing unit, and a vulnerability search unit, and an attack submodule for invoking an attack strategy instruction to initiate the attack instruction on the communication link or control node in the network risk zone;
[0011] The monitoring unit is used to deploy a network packet capture tool and call the network packet capture tool to obtain all communication data packets between the control center and each station equipment;
[0012] The sniffing unit is configured to use an address resolution protocol to disguise an address resolution protocol cache table of the station device to redirect data flow;
[0013] The vulnerability search unit is used to perform port scanning on the station equipment and communication nodes and send a detection data packet; the detection result of the detection data packet is used to indicate that the port is open.
[0014] Optionally, the virtual-reality simulation module includes:
[0015] A simulation submodule is used to simulate the on-site operating environment of the oil and gas production system and simulate the communication control relationship between the control center and the station equipment;
[0016] A physical simulation submodule, configured to receive the attack instruction and perform abnormal operations on corresponding station equipment according to the instruction content of the attack instruction;
[0017] The virtual simulation submodule is used to model the oil and gas production system to obtain a virtual model, and configure data interaction between the virtual model and the physical programmable logic controller; and generate a network topology between the control center and each of the station equipment.
[0018] Optionally, the attack submodule includes:
[0019] A first type attack unit, configured to launch a denial of service attack on the station equipment;
[0020] The second type of attack unit is used to launch a weak password brute force attack on accounts related to the oil and gas production system;
[0021] A third type of attack unit is configured to send forged data or forged control instructions based on communication vulnerabilities or protocol weaknesses in the oil and gas production system;
[0022] The fourth type of attack unit is used to intercept the control data message between the host computer and the station equipment in the oil and gas production system, and replay the control data message at a set time.
[0023] Optionally, the security protection module further includes:
[0024] An audit submodule is used to detect system anomalies in the simulation module and trace back the communication operation log to obtain scheduling instructions to determine the attack path, abnormal data flow direction and source node;
[0025] A firewall submodule, configured to block the flow of abnormal data and isolate the attack path and the source node;
[0026] The controller detection submodule is used to perform safety verification on the key controller of the station equipment; and to call a redundant backup mechanism to restore the control logic of the key controller when the key controller operates abnormally.
[0027] Optionally, the firewall submodule includes:
[0028] The access control unit is used to set an access control policy according to at least one of the IP information, port number and protocol type included in the access control list.
[0029] Optionally, the control center includes:
[0030] Control center management host;
[0031] OPC server, used to obtain on-site operation data of each station equipment;
[0032] A real-time server, used to collect the field operation data obtained by the OPC server in real time and upload it to the control center management host;
[0033] The history server is used to manage and store the field operation data.
[0034] This application also provides a virtual-reality integrated attack and defense drill method for an oil and gas production system, including:
[0035] Monitoring the network risk area of the oil and gas production system, and invoking attack strategy instructions to initiate the attack instructions on the communication links or control nodes in the network risk area;
[0036] receiving the attack instruction, simulating the physical impact of the attack on the equipment in the field operation environment corresponding to the oil and gas production system; the field operation environment includes at least the oil transmission station, gas gathering station, refining station and gas transmission station, as well as the entire chain of production processes between them;
[0037] Detect system anomalies of the station equipment, call the protection strategy matching the system anomaly for joint protection, and generate an attack and defense drill report.
[0038] The present application also provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above-described method when executed by a processor.
[0039] The present application also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps of the above-mentioned method when calling the computer program in the memory.
[0040] The present application provides a virtual-reality integrated attack and defense drill system for an oil and gas production system, comprising: a local attack module, for monitoring the network risk area of the oil and gas production system, and calling attack strategy instructions to initiate the attack instructions on the communication links or control nodes in the network risk area; a virtual-reality simulation module, for simulating the on-site operating environment of the oil and gas production system, maintaining the communication control relationship between the control center and the station equipment; and receiving attack instructions to simulate the physical impact of the station equipment of the oil and gas production system under attack conditions; the on-site operating environment includes at least oil transmission stations, gas gathering stations, refining stations and gas transmission stations, as well as the full-chain production process between them; a security protection module, for detecting system anomalies of the station equipment in the simulation module, and calling a protection strategy matching the system anomaly for linkage protection, and generating an attack and defense drill report.
[0041] This application uses a virtual-reality simulation module to simulate the on-site operating environment of the oil and gas production system, as well as the communication control relationship between the control center and the station equipment. It monitors the network Fengxian District of the oil and gas production system through the local attack module and launches an attack. It supports the simulation of different attack methods and multiple attack chains in complex scenarios, and improves the similarity between the attack and defense simulation scenarios and the actual oil and gas production system. The security protection module simulates the protection strategies adopted when facing different types of attacks, providing a high-fidelity experimental environment for the attack penetration, active defense and emergency response faced by the oil and gas production system in real scenarios, effectively ensuring the security protection capabilities of the oil and gas production system.
[0042] The present application also provides a virtual-reality fusion attack and defense drill method for an oil and gas production system and a computer-readable storage medium, which have the above-mentioned beneficial effects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0044] Figure 1 This is a structural diagram of a virtual-reality integrated attack and defense drill system for an oil and gas production system provided in an embodiment of the present application;
[0045] Figure 2 A schematic diagram of the application process of a virtual-reality integrated attack and defense drill system for an oil and gas production system provided in an embodiment of the present application;
[0046] Figure 3 This is a schematic diagram of the oil and gas station architecture of the oil and gas information physical security attack and defense drill platform provided in an embodiment of the present application;
[0047] Figure 4 This is a schematic diagram of an example of a security attack and defense drill method provided in an embodiment of the present application;
[0048] Figure 5 This is a schematic diagram of the oil and gas information physical security attack and defense drill platform architecture provided in an embodiment of the present application;
[0049] Figure 6 This is a flow chart of a virtual-reality integrated attack and defense drill method for an oil and gas production system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0050] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0051] The object information involved in this application, including but not limited to the object device information, the object personal information, etc., and data, including but not limited to data used for analysis, stored data, displayed data, etc., are all information and data authorized by the object or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the laws, regulations and standards of relevant countries and regions.
[0052] See also Figure 1 , Figure 1This is a schematic diagram of the structure of the virtual-reality integrated attack and defense drill system for the oil and gas production system provided in an embodiment of the present application. The system includes:
[0053] A local attack module, configured to monitor the network risk area of the oil and gas production system and invoke attack strategy instructions to initiate the attack instructions on the communication links or control nodes in the network risk area;
[0054] A virtual-reality simulation module is used to simulate the on-site operating environment of the oil and gas production system, maintain the communication and control relationship between the control center and the station equipment; and receive attack commands to simulate the physical impact of the station equipment of the oil and gas production system under attack conditions. The on-site operating environment includes at least the oil transfer station, gas gathering station, refining station, and gas transmission station, as well as the entire chain of production processes between them.
[0055] The security protection module is used to detect system anomalies of the station equipment in the simulation module, call the protection strategy matching the system anomaly to perform linkage protection, and generate an attack and defense drill report.
[0056] In a feasible embodiment, the local attack module may include a monitoring submodule including a monitoring unit, a sniffing unit and a vulnerability search unit, and an attack submodule for calling attack strategy instructions to initiate the attack instructions on the communication link or control node in the network risk area.
[0057] The monitoring submodule includes a monitoring unit, a sniffing unit, and a vulnerability search unit. The monitoring unit is used to deploy a network packet capture tool and call the network packet capture tool to obtain all communication data packets between the control center and each station equipment;
[0058] a sniffing unit, configured to disguise an address resolution protocol cache table of the station device using an address resolution protocol to redirect data flow;
[0059] The vulnerability search unit is used to perform port scanning on the station equipment and communication nodes and send a detection data packet; the detection result of the detection data packet is used to indicate whether the port is open.
[0060] During the application process, the monitoring unit is used to monitor various communication activities between the control center and each station in the oil and gas production system, capturing various data traffic transmitted in the network, including information interaction between different devices, operator login requests, file transfer behavior, etc.; by monitoring the above traffic, valuable information is extracted, such as the network topology across stations, the role and function distribution of different device nodes, and whether there are abnormal communication patterns or frequently transmitted sensitive data streams. In addition, the monitoring unit can also deploy network packet capture tools to set the interface of the internal network of the oil and gas production system to promiscuous mode, capture all data packets flowing through the network between the control center and each station, and obtain real-time information on the communication content in the oil and gas production control link.
[0061] At the same time, the sniffing unit is used to analyze data packets in the target network, extracting key sensitive information contained therein, and assisting in obtaining user login credentials, unencrypted file contents, network configuration details, etc., providing a breakthrough for subsequent attacks on key control links. Specifically, Address Resolution Protocol (ARP) spoofing technology can be used to tamper with the ARP cache table of key node devices in the oil and gas system by forging ARP response packets, thereby redirecting data flows originally sent to normal IP addresses to designated devices. This allows traffic sniffing of production control data, station command data flows, etc., to extract sensitive system information and key control commands.
[0062] Based on monitoring and sniffing, vulnerability search units are used to conduct vulnerability analysis on oil and gas system network equipment and control systems, including detecting equipment vulnerabilities that have not been patched in a timely manner, identifying user accounts with weak passwords, and discovering areas with improper network access control settings, thereby exploring key points that can be broken through and threatening the overall production control and station-field linkage security. Specifically, based on port scanning technology, port scanning can be performed on hosts and key communication nodes within the oil and gas production network. By sending specific detection data packets, open ports can be determined based on the response of the target host, and the corresponding service characteristics can be further analyzed to identify possible known security vulnerabilities, thereby locking in potential risk points that affect the safety of the coordinated operation of the control center and the station field.
[0063] The specific type of attack instructions issued by the local attack module or the above-mentioned attack submodule is not limited here. In a feasible implementation, it may include:
[0064] A first type attack unit, configured to launch a denial of service attack on the station equipment;
[0065] The second type of attack unit is used to launch a weak password brute force attack on accounts related to the oil and gas production system;
[0066] A third type of attack unit is configured to send forged data or forged control instructions based on communication vulnerabilities or protocol weaknesses in the oil and gas production system;
[0067] The fourth type of attack unit is used to intercept the control data message between the host computer and the station equipment in the oil and gas production system, and replay the control data message at a set time.
[0068] That is, the first type of attack unit can be used to launch a denial of service attack, the second type of attack unit can be used to launch a weak password brute force attack, the third type of attack unit can be used to launch a false data injection attack, and the fourth type of attack unit can be used to launch a replay attack.
[0069] Denial of service attacks can target key nodes such as oil and gas production control centers and station control servers by sending massive network requests or large amounts of abnormal data streams to them, causing the target system resources to be exhausted or its operation to be blocked, making it impossible to continue to effectively control the oil and gas transportation, compression, processing and other processes, thereby causing business interruptions, data anomalies and even station shutdowns. Specifically, the Hping3 tool is mainly used to implement traffic flooding attacks on key nodes such as the oil and gas control center server and each station monitoring host. By writing automated scripts, Hping3 continuously sends a large number of customized TCP SYN packets to the target device. By adjusting parameters such as the number and rate of packets sent, the network bandwidth resources of the target site are quickly exhausted, resulting in business interruptions such as oil and gas production scheduling instructions and remote monitoring data uploads, seriously affecting the continuity of gas and oil transmission operations.
[0070] Weak password brute force attacks can target key accounts in the oil and gas system, such as dispatch control accounts and remote operation and maintenance accounts, by attempting to crack logins using weak password combinations in batches. If the target node is protected by a weak password, the attacker can illegally obtain control permissions, thereby manipulating station equipment, tampering with production instructions, or stealing sensitive data. Specifically, based on the analysis results of the oil and gas production network environment during the sniffing process, a more targeted username and password dictionary is generated. The Hydra tool is used to brute force the IP address, service port, user list, and password dictionary path of the selected target server, attempting to illegally log into the oil and gas control center account or the station equipment backend to obtain sensitive control permissions and thus manipulate key equipment such as pipeline valves and pump units.
[0071] False data injection attacks exploit communication vulnerabilities or protocol weaknesses in oil and gas production monitoring systems to send forged sensor data or control commands to field controllers (such as RTUs and PLCs), misleading the control center into making incorrect judgments about pipeline pressure, valve status, and other factors, potentially leading to abnormal operations, oil and gas leaks, or equipment damage. Specifically, by placing an attacking machine in the communication path between oil and gas production field equipment (such as pressure sensors and temperature sensors) and the control center or RTU, the attacker uses the Ettercap tool to intercept and tamper with the transmitted sensor data or control commands in real time, injecting false data such as forged oil and gas flow and pipeline pressure into the control system, inducing the system to respond incorrectly, causing production anomalies or even safety accidents.
[0072] Replay attacks intercept legitimate data packets between the controller and the host computer or field equipment in the oil and gas production control chain, then replay these packets at the appropriate time, causing the system to repeatedly execute inappropriate operations, resulting in abnormal oil and gas flow regulation, abnormal pressure increases, or control logic errors, thereby disrupting normal production processes. In one feasible implementation, the replay attack is based on capturing key network traffic and control packets of the oil and gas production system, saving them to a local file, and then using the Scapy tool to write an attack script. At the appropriate time, the saved historical packets are resent to the target controller or field control system, tricking the system into repeatedly executing incorrect control instructions, causing serious consequences such as abnormal oil and gas transmission processes and uncontrolled valve opening and closing.
[0073] Under normal circumstances, the virtual-reality simulation module simulates the on-site operating environment of the oil and gas production system, maintaining stable coordination between the control center and key equipment at each station (such as oil pumps, compressor units, pipeline valves, and metering instruments). The controller ensures that each functional module is on standby and linked normally. Upon receiving an external attack command, the module simulates the physical impact of the station equipment of the oil and gas production system under attack conditions. For example, the virtual-reality simulation module can perform abnormal operations on the production model based on the command content, such as driving the pump at a speed beyond the normal operating range, opening or closing the pipeline valve in reverse, and incorrectly adjusting the oil pressure or gas flow rate, causing equipment overload, system failure, or transmission interruption. This truly restores the physical destructive effects caused by cyber attacks and verifies the vulnerability of each node in the oil and gas production network topology.
[0074] The physical simulation module includes the oil and gas transmission station on-site process unit, on-site control unit, network security management unit, and central control unit, such as Figure 3 The virtual simulation module includes the refinery station unit model, control model, virtual-reality fusion network and data analysis model. The formulas for each part are as follows:
[0075] Among them, the unit module includes a reactor, a separator, and a stripping tower.
[0076] The reactor is modeled as follows:
[0077] ;
[0078] in, is the jth chemical reaction rate, is the temperature-dependent reaction rate constant, is the partial pressure of the i-th reactant, is the reaction order of the i-th component in the j-th reaction, is the frequency factor of the jth reaction, is the activation energy of the jth reaction, R is the gas constant, and T is the temperature in the reactor.
[0079] The separator is modeled as follows:
[0080] ;
[0081] in, is the gas phase partial pressure, is the mole fraction of component i in the liquid phase, is the saturated vapor pressure of component i at temperature T.
[0082] ;
[0083] in, , , is the Antoine coefficient of component i, and T is the liquidus temperature (in °C). This relationship forms the thermodynamic basis of gas-liquid partitioning.
[0084] ;
[0085] in, is the gas phase mole fraction is the total pressure of the gas phase in the separator.
[0086] The stripping column is modeled as follows:
[0087] ;
[0088] in, The thermal power provided to the reboiler, is the heat transfer coefficient, is the heat transfer area, Set the temperature threshold for heating start, is the liquid temperature at the bottom of the tower.
[0089] Control strategy modeling:
[0090] ;
[0091] in, is the controller output, is the error signal between the setpoint and the process variable, 、 、 are the gain coefficients of proportional, integral and differential respectively.
[0092] The virtual-reality fusion network and data analysis model are as follows:
[0093] ;
[0094] in, It represents the sensor data perception delay, which is the delay from the physical device sensing the environment to generating data. Indicates network transmission latency, including the time it takes to transmit data from a physical system to a virtual system or vice versa, and is affected by factors such as network bandwidth and transmission distance. It represents the processing delay in the virtual system and represents the time required for data processing and simulation calculation. It represents the actuator response delay, which refers to the time it takes for a command to be transmitted to the physical system and take effect.
[0095] ;in is the time deviation and T is the period.
[0096] ;
[0097] in, represents the consistency deviation, is the total delay of each data transfer. As the system increases, the consistency of the system decreases, so it is necessary to reduce the delay of each part. , thereby improving the consistency of virtual and real fusion.
[0098] The attack simulation model is as follows:
[0099] The attacker's target attack variable changes due to the attack. This variable consists of the process variable under normal circumstances and the attack vector of the network attack, and its form is:
[0100] ;
[0101] is the attacker’s target attack variable, is the process variable under normal conditions of the system, is the attacker’s attack vector. Based on the CSTR control system model and the control variables and controlled variables in the control loop, each type of network attack can be simulated by changing the process variables in the system. The respective simulation forms are shown in Table 1.
[0102] Table 1 Simulation forms of different types of network attacks
[0103]
[0104] in 、 、 and They are the sensor values, command setting values, jacket coolant flow values and execution actions of the four target attack variables. 、 、 They are the sensor value, set value and jacket coolant temperature value under normal conditions respectively. 、 and These are the attack vectors of false data injection attack on sensors, malicious instruction injection attack, and false data injection attack on actuators.
[0105] The security protection module is used to detect system anomalies of the station equipment in the simulation module and call a protection strategy that matches the system anomaly to perform linkage protection.
[0106] In a feasible implementation, the security protection module may include:
[0107] An audit submodule is used to detect system anomalies in the simulation module and trace back the communication operation log to obtain scheduling instructions to determine the attack path, abnormal data flow direction and source node;
[0108] A firewall submodule, configured to block the flow of abnormal data and isolate the attack path and the source node;
[0109] The controller detection submodule is used to perform safety verification on the key controller of the station equipment; and to call a redundant backup mechanism to restore the control logic of the key controller when the key controller operates abnormally.
[0110] The audit submodule quickly traces back relevant communication and operation logs, combines station equipment with upper-level dispatch instructions, analyzes attack paths, abnormal flows, and source nodes, and provides a basis for subsequent precise protection decisions; the firewall submodule blocks suspicious traffic in real time based on the segmentation rules in the network topology, isolates the attack propagation path, prohibits malicious data packets from invading the station control network, and restricts unauthorized access; the controller detection submodule is simultaneously enabled to verify the operating status, program code, and data consistency of key equipment controllers. Once tampering or abnormal operation is discovered, the original control logic is immediately restored based on the redundant backup mechanism to ensure the continuous and stable operation of the oil and gas transmission link. The overall protection measures are aimed at multiple threat scenarios such as denial of service attacks, weak password brute force attacks, false data injection and replay attacks, and realize multi-node and layered dynamic protection in the oil and gas production network environment.
[0111] The audit submodule comprehensively deploys the logging function on the oil and gas control center server, each station network equipment and key application system nodes, and records user operation behaviors in detail, including login time, access resources, execution of commands and other key operations, and associates network connections, IP addresses, timestamps and other information. Combined with the multi-level network topology of oil and gas production, it conducts full-link correlation analysis and traces the attack path and source node. For example, it accurately identifies the location where the abnormal IP first appears and its communication relationship with upstream and downstream station equipment, providing a decision-making basis for cross-station precision protection. In addition, it integrates intrusion detection functions, and matches abnormal patterns in network traffic with known attack features in real time based on the feature library. For example, when a SQL injection feature string is detected, it automatically triggers an alarm and pushes it to the central platform.
[0112] The anomaly detection of the audit submodule realizes anomaly detection in the oil and gas production system by mining the spatiotemporal causal dependencies between heterogeneous nodes. The model is as follows:
[0113] In oil and gas production systems, data is typically collected from N sensors and actuators to form multivariate time series data, where each node sequence is represented as follows:
[0114] ;
[0115] in represents the data of node i at time t, n represents the total number of nodes, and each node represents a variable obtained by a sensor or actuator.
[0116] There are several types of relationships between sensors and actuators, defined as different edge types. The structure of the heterogeneous graph can be summarized as follows:
[0117] ;
[0118] in represents a node set, represents the edge set, Represents a set of node types, Represents a set of edge types.
[0119] In a heterogeneous graph, the adjacency matrix can be decomposed into multiple sub-matrices, each corresponding to a different node or edge type. The adjacency matrix is defined as:
[0120] ;
[0121] The adjacency matrix Indicates that a fixed node type and edge type The same graph is generated.
[0122] A heterogeneous multivariate time series is defined as follows:
[0123] ;
[0124] in Represents the relationship at time t data.
[0125] Sensors and actuators form a multi-relationship interaction network, and the relationships between sensors often reflect process dependencies. Analyze complex multivariate time series data based on the following model:
[0126] ;
[0127] ;
[0128] in and is the lag order, and is the center vector of the kernel function, and is the weight of the core center, is the Gaussian kernel, is the width of the kernel; is the residual, which represents the model prediction error.
[0129] By constructing the prediction errors (such as mean square error or residual sum of squares) of the above two models, the F test statistic is constructed as follows:
[0130] ;
[0131] where m is the number of parameter differences between the autoregressive model and the expanded model, is the sample size, is the total number of parameters in the expanded model, is the residual sum of squares of the autoregressive model, is the residual sum of squares of the expanded regression model.
[0132] We then introduced relation-specific transformations based on GNN-Film and used feedforward neural network parameters as weights to adjust the embedding. In a multi-layer convolutional network, the inter-layer connection structure of the temporal GNN-Film layer is as follows:
[0133] ;
[0134] in Represents the characteristics of each layer, represents a nonlinear activation function, Representing relationships The neighbor node index set under represents the parameters of the affine transformation, Represents a self-join of a single node. The role of is to scale the features of each dimension, that is, dynamically adjust the "attention" or "importance"; It is used to offset the features of each dimension and introduce non-zero center adjustment to enhance the nonlinear expression ability of the model.
[0135] In order to better capture the dependencies in sequence data and explicitly determine the importance of different variables at different time points in the control graph, a GRU-based attention mechanism is introduced.
[0136] ;
[0137] in Control the weights of the current hidden state and candidate state, is the weight calculated by the attention mechanism, which is used to control the weight of the input at the current moment. is the output at the current moment, It is the reset gate. is the hidden state at the previous moment, represents element-wise multiplication, and is the weight matrix and tanh is the activation function.
[0138] Now that the construction is complete, the collected data can be detected for anomalies and alarms can be generated.
[0139] The firewall submodule may include an access control unit for setting access control policies based on at least one of the IP information, port number, and protocol type contained in the access control list. Specifically, the access control list (ACL) technology may be used, combined with the zoning of the oil and gas production control network, to set fine-grained access control policies based on conditions such as source IP, destination IP, port number, and protocol type. For example, traffic from suspicious IP segments may be prohibited from entering the dispatch center area, or only specific ports such as the Web management port may be allowed to pass through the station subsystem. At the same time, combined with the state detection mechanism, the TCP connection life cycle is dynamically tracked, from connection establishment to data transmission to closure, and abnormal connection status data packets are blocked in real time to prevent attackers from exploiting topology link vulnerabilities to move laterally.
[0140] The controller detection submodule, based on a data verification mechanism, regularly compares the program code of each station controller with the standard backup stored in the central repository to detect tampering or unauthorized modifications. It also monitors the controller's operating status in real time, including CPU load, memory usage, network interface traffic, and the health of key processes. If an operational anomaly is detected or indicators deviate from expected thresholds, a recovery strategy combining full and incremental backups is immediately activated. This ensures rapid restoration of equipment functionality in the multi-node, multi-link oil and gas transmission system, safeguarding the continuity and stability of the overall system.
[0141] The embodiment of the present application utilizes a virtual-reality simulation module to simulate the on-site operating environment of the oil and gas production system, as well as the communication control relationship between the control center and the station equipment. It monitors the network Fengxian District of the oil and gas production system through the local attack module and launches an attack. It supports the simulation of different attack methods and multiple attack chains in complex scenarios, improves the similarity between the attack and defense simulation scenarios and the actual oil and gas production system, and simulates the protection strategies adopted when facing different types of attacks through the security protection module. It provides a high-fidelity experimental environment for the attack penetration, active defense and emergency response faced by the oil and gas production system in real scenarios, effectively ensuring the security protection capabilities of the oil and gas production system.
[0142] See also Figure 2 , Figure 2 This is a schematic diagram of the application process of a virtual-reality integrated attack and defense drill system for an oil and gas production system provided in an embodiment of the present application. The process includes:
[0143] The drill report consists of three parts: preparation, implementation, and summary. During the drill summary, the attack results report, release results report, and protection rectification report together constitute the attack and defense drill report.
[0144] During drill preparation, the attack and defense organization, as well as the attackers and defenders, must be determined. This includes the drill objectives and scope, including the multi-layered network of the oil and gas production system, virtual and physical simulation environments, the development of an attack and defense drill demonstration plan, and verification and testing of the plan's feasibility. The attacker must confirm the effectiveness of attack techniques and tools and deploy local attack modules. The defender must provide information as required, conduct asset analysis, perform security hardening, and verify the effectiveness of protective measures and tools.
[0145] During the drill, the attacker monitors and sniffs the network, identifying weak links and breaching gateways. They also perform vulnerability scanning and exploitation to gain access rights and control the target host. The defender then performs network anomaly detection and configures network policies to block the attack. If the attack is successful, they acquire data and permissions, issuing malicious commands to disrupt production. They also analyze protocol vulnerabilities and target industrial control equipment, injecting malicious commands into the controllers. At this point, the defender determines a network anomaly has been detected and configures network policies to block the attack. The drill terminates if a device malfunctions, data anomalies occur, or the system issues an alarm.
[0146] In a feasible embodiment, the attack and defense drill system may also include a virtual simulation sub-module for modeling the oil and gas production system to obtain a virtual model, and configuring data interaction between the virtual model and the physical programmable logic controller; generating a network topology structure between the control center and each of the station equipment.
[0147] The virtual simulation submodule leverages modeling and simulation technology, based on the complex network topology between the control center and multiple field nodes in the oil and gas production system. It can construct a multi-layer, multi-protocol hybrid system environment, covering different types of equipment, communication links, and control logic, and can highly replicate the actual operation scenarios of oil and gas production. At the same time, it comprehensively utilizes a combination of various attack methods and strategies to simulate complex cross-domain and cross-layer attack processes, such as multi-point simultaneous denial of service attacks, link hijacking, and coordinated attacks with false data injection, to evaluate the system's defense capabilities under highly complex threat conditions.
[0148] The virtual simulation submodule not only simulates attacks but also collaborates with the audit and firewall submodules during the simulation process. The traffic, communication behavior, and abnormal event data generated by simulated attacks serve as a crucial sample source for training and optimizing the abnormal behavior recognition model within the audit submodule, improving the accuracy of audit detection in complex oil and gas environments. Furthermore, the firewall submodule can adjust access control policies and refine its intrusion detection signature library in real time based on new attack traffic characteristics identified during virtual simulation, thereby enhancing dynamic protection against specific threats to oil and gas production.
[0149] There is no restriction on how the virtual simulation submodule constructs the virtual model. It can use Matlab to model the complex process flows, station layouts, and control scenarios in oil and gas production. By introducing OPC communication technology, seamless data interaction between the virtual model and the physical programmable logic controller (PLC) is achieved, enabling the virtual model to collect the PLC operating status in real time and dynamically feed back the simulation results to the PLC, supporting closed-loop control simulation of the production process.
[0150] Virtual models can be built on the OMNET++ platform, creating a virtual network node system consistent with the structure of oil and gas stations and control centers. This allows for accurate simulation of communication characteristics in industrial control networks, such as data transmission latency, congestion, and node failures. OMNET++'s rich simulation capabilities can replicate the data interaction characteristics of multi-layered network environments.
[0151] In addition, with the help of the EXT interface, the interconnection between the virtual network and the real hardware equipment is achieved, and the virtual simulation environment and the actual oil and gas production network are deeply integrated, which greatly improves the authenticity and experimental effect of complex attack simulations and provides support for attack and defense drills in complex network topology environments in the oil and gas industry.
[0152] It can be seen that this embodiment is equivalent to building a virtual-real integrated oil and gas information physical security attack and defense drill platform, which truly restores the overall environmental architecture of the oil and gas production system, covering the control center, virtual-real simulation module, local attack module, virtual simulation sub-module and security protection module.
[0153] The control center, as the core management and dispatching unit, is responsible for centralized command and real-time monitoring of all stations in the oil and gas system. The supporting safety management center is responsible for system security protection and abnormal response, ensuring the safe and stable operation of the platform.
[0154] The virtual-reality simulation module simulates the on-site operating environment of the oil and gas production system, including oil transfer stations, gas gathering stations, refining stations, and gas transmission stations. It comprehensively simulates the entire production chain from oil and gas resource collection, preliminary processing, transportation to final refining and processing, and constructs the corresponding network topology relationship to reflect the characteristics of complex distributed systems in actual oil and gas production.
[0155] The local attack module actively launches attack tests on the oil and gas production network through the attack nodes deployed inside the platform to evaluate the system's security protection capabilities and response mechanisms. The corresponding security protection module is used to detect system anomalies of the station equipment in the simulation module and call the protection strategy matching the system anomaly for linkage protection.
[0156] The virtual simulation sub-module further expands the functional boundaries of the platform. Combining modeling simulation with physical interaction technology, it supports the conduct of confrontation drills of various network attacks and defense strategies in complex oil and gas production scenarios, and enhances the platform's verification and drill capabilities when facing complex topological structures and advanced attack methods.
[0157] It should be noted that in the above embodiment, the control center described is responsible for unified monitoring and management of the entire system, including the control center management host, OPC server, real-time server and history server:
[0158] The OPC server is based on the OPC standard protocol to achieve data interaction and sharing between devices and systems from different manufacturers, ensuring that the data collected by field equipment can be efficiently and accurately transmitted to subsequent processing links;
[0159] The real-time server collects various operational data from oil and gas production sites in real time, processes and analyzes them quickly, and instantly distributes the latest system status information to the control center management host and related systems, enabling real-time control of the site status.
[0160] The historical server is responsible for the storage and management of various historical data generated during the operation of the system, and retains them in full according to the time series to provide a basis for subsequent data tracing, anomaly analysis and decision support.
[0161] In a feasible implementation, the security attack and defense drill system may also include a security management center responsible for the security protection of the platform system, including a security management host, an audit system, a situational awareness system and a firewall system.
[0162] The security management host is used to uniformly configure and manage security devices and modules, formulate, update and issue security policies, and ensure the security coordination of all nodes in the system;
[0163] The audit system is used to record and audit various network and device operations and events in detail, covering access behavior, operation logs, etc., to promptly identify potential security threats and illegal operations;
[0164] The situational awareness system is used to comprehensively collect multi-source data from the exercise platform, conduct real-time analysis and processing, comprehensively perceive the system operation situation, and dynamically display the system security status and risk warnings through a visual interface;
[0165] The firewall system is deployed at the network boundary to block external illegal access and malicious attacks based on preset security policies, prevent unauthorized device access or malware intrusion, and ensure the security of internal networks and devices.
[0166] The situation awareness system includes a situation detection model, a situation understanding model, and a situation prediction model.
[0167] The key to situational awareness lies in the awareness of system topology information and measurement data, which enables the extraction of key information about system state and deviation. The system state can be solved by filtering the measurement data using state estimation technology, as follows:
[0168] ;
[0169] In the above formula, z e With z g is the measurement vector; h e With h g is the measurement model; x e with x g is the state vector; R e With R g is the measurement covariance matrix; c(x e , x g ) is an equality constraint.
[0170] Situation understanding is to analyze the historical deviations of the system and reveal the future operating trends of the system. It requires understanding the perceived system deviations, including understanding of historical time series deviations and understanding of future operating trends.
[0171] First of all, Time period deviation Perform normalization operation, which can be written as:
[0172] ;
[0173] Where: is the normalized system deviation at time n; d n is the system deviation at time n; and They are The maximum and minimum system deviations during the time period.
[0174] The situation prediction model strengthens and filters information features based on convolution operations, as follows:
[0175] ;
[0176] In the formula 、 、 are the elements in matrices x, w, and y, where x is the convolution calculation input matrix, w represents the convolution kernel of size M×N, and y is the convolution calculation output matrix.
[0177] Then, the activation function is introduced to enhance its nonlinear fitting and representation capabilities, as follows:
[0178] ;
[0179] In a feasible implementation, the oil transfer station, gas gathering station, refining station and gas transmission station simulated by the virtual-reality simulation module are divided into four submodules according to their functions: station control center, station control safety center, field control and field process. Figure 3 and Figure 4 , Figure 3 This is a schematic diagram of the oil and gas station architecture of the oil and gas information physical security attack and defense drill platform provided in the embodiment of this application. Figure 4 This is a schematic diagram illustrating an example of a security attack and defense drill method provided in an embodiment of the present application.
[0180] The station control center is equipped with a programmable logic controller programming module, a data acquisition and monitoring module, and an industrial automation control module to realize the automated control and data monitoring of the production process within the station;
[0181] The station control security center is equipped with an industrial audit module, an industrial firewall module, and a controller detection module, which are responsible for the security protection and abnormality repair of equipment and networks within the station;
[0182] The field control includes a programmable logic controller (PLC) and a human-machine interface (HMI) for realizing on-site control and interactive operation of the process;
[0183] The on-site process covers various sensors, valves, pumps and other key process equipment, fully simulating the actual process of oil and gas production operations.
[0184] Among them, for the station control center, the programmable logic controller programming module is responsible for programming and debugging the programmable logic controller (PLC), and uses the written control program to realize the automated control of various equipment and processes in the production process;
[0185] The data acquisition and monitoring submodule collects various data in the production process in real time. Through the monitoring interface, operators can check the operating status and key parameters of the production process at any time to ensure the normal operation of the system;
[0186] The industrial automation control submodule performs comprehensive management and scheduling of the entire station system, integrates various control tasks in the production process, and coordinates the collaborative work of different equipment, thereby realizing the automation and optimization of the production process.
[0187] For the station control security center, it can include an industrial audit module, an industrial firewall module, and a controller detection module, specifically including:
[0188] The industrial audit module is responsible for recording and auditing various operations and events in the industrial network, monitoring access to industrial equipment and systems, recording equipment operation logs, and promptly identifying potential security threats and illegal operations;
[0189] The industrial firewall module is deployed at the network boundary and is responsible for blocking external illegal network access and malicious attacks. According to the preset security policy, it prevents unauthorized devices or malware from entering the internal LAN, thus ensuring internal network security.
[0190] The controller detection module monitors the integrity of the programmable logic controller (PLC) in real time, detects whether there is program tampering or other abnormal conditions, and immediately restores the backup program once an abnormality is found to ensure the normal operation of the controller and system security.
[0191] For field control, it can include programmable logic controllers and human-machine interfaces:
[0192] The programmable logic controller executes various control instructions according to the pre-written control program, accurately controls the actuators in the production process, and ensures that each process operation is carried out according to the predetermined process;
[0193] The human-machine interaction interface provides an intuitive operation interface, which displays key information such as equipment operating status and process parameters in real time, making it easy for operators to monitor the production process and make necessary adjustments and controls.
[0194] On-site processes can include key process equipment such as various sensors, valves, and pumps. These sensors are responsible for collecting real-time physical quantity data during the production process and transmitting the collected data to other modules for analysis and processing, providing real-time monitoring support for the system. Controlled mechanisms such as valves and pumps receive control signals and simulate the equipment's operating status in actual production environments. By precisely controlling the start and stop of various equipment, real-time control and regulation of the oil and gas production process is achieved.
[0195] The embodiment of the present application discloses a method for attack and defense drill of oil and gas information physical security, and takes a specific attack and defense drill embodiment as an example. Figure 4 As shown:
[0196] First, the monitoring unit is used to monitor various communication activities and data traffic within the target network, including information exchanges between different devices, user login requests, and file transfers. By monitoring this traffic, valuable information is obtained, such as the network topology, the roles and functions of different devices, and whether there are any abnormal communication patterns or frequently transmitted sensitive data. At the same time, the sniffing unit is used to analyze the data packets in the target network and the information contained therein, helping to obtain user login credentials, unencrypted file contents, network configuration information, and other information, thereby finding a breakthrough for the next attack. Based on the monitoring and sniffing, the vulnerability search unit is used to search for weak points in the system and, based on the collected information, analyze the security of each device and system in the network.
[0197] Through the above steps, we successfully searched for the control center management host with a weak password vulnerability in the experimental platform, and then used the attack host to call the weak password brute force attack in the attack library to attack it, crack the password, and then obtain control permissions; the attack host used the obtained permissions to send malicious instructions to the station control center to change the normal production process.
[0198] The station control host responds to the control instructions sent by the control center and sends the malicious instructions to the programmable logic controller in the field control. After receiving the malicious instructions, the programmable logic controller will mistakenly process the malicious instructions as normal control instructions because it follows the preset instruction execution logic. The programmable logic controller adjusts its internal logic control program according to the content of the malicious instructions and generates illegal control instructions for the controlled mechanism in the process simulation module.
[0199] After receiving illegal control instructions from the field control module, the controlled mechanism in the field process module will act accordingly. These illegal instructions may require the oil pump to operate at an excessive speed, change direction, or execute an incorrect operating procedure. These illegal actions can cause production model failures, resulting in equipment damage and interruptions to the production process.
[0200] When the system is attacked by an intrusion, production data becomes abnormal. The audit module of the station control center first generates an alarm and uploads it to the security management center of the control center. The security management center then uses intrusion detection technology to disassemble and analyze each data packet transmitted in the network, identifying key information and potential threats. By correlating and analyzing key data such as network connections, IP addresses, and timestamps in the logs, the source of the attack is traced, and the time when the abnormal IP address first appeared and its communication records with other devices are determined, providing a basis for precise protection. The firewall module then uses access control list technology based on the audit information. Based on preset access control rules based on source IP address, destination IP address, port number, protocol type, and other conditions, it constructs an access control list to prohibit the entry of traffic from specific malicious IP address segments in order to block the source of the attack.
[0201] After failing to attack the management host of the control center, the attack host turns to analyzing the target industrial control network protocol vulnerabilities and exploits the protocol vulnerabilities to directly attack the controller. During the communication process, the legitimate data packets transmitted between the controller and other devices are intercepted and saved as files. The attack script is written using Scapy to read and tamper with the previously saved message files, and then resend these messages to the controller at the appropriate time. Since the controller cannot distinguish between the replayed messages and normal new messages, it may perform repeated or incorrect operations, resulting in incorrect control actions, data confusion or other abnormal conditions in the system.
[0202] When the controller is attacked, the protection steps are similar. Auditing and firewalls are used to block and isolate the source of the attack. After that, since the controller integrity monitoring and recovery module uses a combination of full backup and incremental backup to regularly back up data and operating status, it can quickly restore from the most recent backup and restore the normal operation of the controller.
[0203] Finally, the situational awareness system integrates abnormal data and various system information, including network topology information, equipment operating status information, etc., to generate detailed attack and defense logs, recording key information such as the time of attack initiation, attack type, involved IP addresses, affected system components, etc. At the same time, using visualization technology, the attack and defense process is displayed in an intuitive graphical interface.
[0204] See also Figure 5 , Figure 5 This embodiment of the application discloses an oil and gas cyber-physical security attack and defense drill platform that simulates the complex network architecture of oil and gas production systems and comprehensively presents the IT / OT coupling risk transmission process. The platform includes:
[0205] A virtual-reality integrated oil and gas cyber-physical security attack and defense drill platform has been built to realistically simulate the oil and gas production system environment architecture. It consists of four parts: a control center, a virtual-reality simulation module, a local attack module, and a virtual simulation submodule. The control center, as the core management unit, is responsible for the centralized dispatch and monitoring of the entire oil and gas system, while the security management center focuses on system security protection to ensure the safe and stable operation of the entire platform. The virtual-reality simulation module includes four stations: an oil transfer station, a gas gathering station, a refining station, and a gas transmission station. It simulates the entire process of oil and gas production system operations, from the collection and initial processing of oil and gas resources to transportation and final processing. The local attack module uses locally deployed attack aircraft to attack the experimental platform, testing the security protection capabilities of the oil and gas production system. The virtual simulation submodule greatly expands the functional boundaries of the experimental platform, enabling it to simulate complex network attacks and defense confrontations in complex production scenarios. Based on the integration of virtual and real, it can simulate various complex network attack methods and conduct attack and defense drills.
[0206] See also Figure 6 The present application further provides a virtual-reality fusion attack and defense drill method for an oil and gas production system, based on the virtual-reality fusion attack and defense drill system for an oil and gas production system described in the above embodiment, comprising:
[0207] S601: Monitoring a network risk area of the oil and gas production system, and invoking an attack strategy instruction to initiate the attack instruction on a communication link or control node in the network risk area;
[0208] S602: Receive the attack instruction and simulate the physical impact of the attack on the equipment in the field operation environment of the oil and gas production system. The field operation environment includes at least the oil transmission station, gas gathering station, refining station, and gas transmission station, as well as the entire production chain between them.
[0209] S603: Detecting system anomalies of the station equipment, invoking a protection strategy matching the system anomaly to perform linkage protection, and generating an attack and defense drill report.
[0210] In addition, this application also proposes a virtual-real integrated oil and gas information physical security attack and defense drill method, which uses modeling and simulation technology to construct complex network topology structures and diverse system environments, simulate various complex scenarios, and comprehensively use a combination of multiple attack technologies to simulate complex attack aspects.
[0211] The present application also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the method described in the above method embodiment.
[0212] It is understandable that if the method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and executes all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.
[0213] The computer-readable storage medium provided in this embodiment includes the above-mentioned method, and the effect is the same as above.
[0214] The present application also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the method described in the above embodiment are implemented.
[0215] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems provided in the embodiments, since they correspond to the methods provided in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0216] This document uses specific examples to illustrate the principles and implementation methods of this application. The description of the above examples is only intended to help understand the method and core ideas of this application. It should be noted that for those skilled in the art, without departing from the principles of this application, various improvements and modifications can be made to this application, and such improvements and modifications also fall within the scope of protection of this application.
[0217] It should also be noted that, in this specification, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
Claims
1. A virtual-reality fusion attack and defense drill system for oil and gas production systems, characterized by: include: A virtual-reality simulation module is used to simulate the on-site operating environment of the oil and gas production system and maintain the communication and control relationship between the control center and the station equipment; and receiving attack instructions to simulate the physical impact of the station equipment of the oil and gas production system under attack conditions; the on-site operating environment at least includes the oil transmission station, gas gathering station, refining station and gas transmission station, as well as the entire chain of production processes between them; A local attack module, configured to monitor the network risk area of the oil and gas production system and invoke attack strategy instructions to initiate the attack instructions on the communication links or control nodes in the network risk area; The security protection module is used to detect system anomalies of the station equipment in the simulation module, call the protection strategy matching the system anomaly to perform linkage protection, and generate an attack and defense drill report.
2. The system according to claim 1, wherein: The virtual-reality simulation module includes: A simulation submodule is used to simulate the on-site operating environment of the oil and gas production system and simulate the communication control relationship between the control center and the station equipment; A physical simulation submodule, configured to receive the attack instruction and perform abnormal operations on corresponding station equipment according to the instruction content of the attack instruction; The virtual simulation submodule is used to model the oil and gas production system to obtain a virtual model, and configure data interaction between the virtual model and the physical programmable logic controller; and generate a network topology between the control center and each of the station equipment.
3. The system according to claim 1, wherein: The local attack module includes: A monitoring submodule comprising a monitoring unit, a sniffing unit, and a vulnerability search unit, and an attack submodule for invoking an attack strategy instruction to initiate the attack instruction on the communication link or control node in the network risk zone; The monitoring unit is used to deploy a network packet capture tool and call the network packet capture tool to obtain all communication data packets between the control center and each station equipment; The sniffing unit is configured to use an address resolution protocol to disguise an address resolution protocol cache table of the station device to redirect data flow; The vulnerability search unit is used to perform port scanning on the station equipment and communication nodes and send a detection data packet; the detection result of the detection data packet is used to indicate that the port is open.
4. The system according to claim 3, characterized in that The attack submodule includes: A first type attack unit, configured to launch a denial of service attack on the station equipment; The second type of attack unit is used to launch a weak password brute force attack on accounts related to the oil and gas production system; A third type of attack unit is configured to send forged data or forged control instructions based on communication vulnerabilities or protocol weaknesses in the oil and gas production system; The fourth type of attack unit is used to intercept the control data message between the host computer and the station equipment in the oil and gas production system, and replay the control data message at a set time.
5. The system according to claim 1, wherein: The security protection module also includes: An audit submodule is used to detect system anomalies in the simulation module and trace back the communication operation log to obtain scheduling instructions to determine the attack path, abnormal data flow direction and source node; A firewall submodule, configured to block the flow of abnormal data and isolate the attack path and the source node; The controller detection submodule is used to perform safety verification on the key controller of the station equipment; and to call a redundant backup mechanism to restore the control logic of the key controller when the key controller operates abnormally.
6. The system according to claim 5, characterized in that The firewall submodule includes: The access control unit is used to set an access control policy according to at least one of the IP information, port number and protocol type included in the access control list.
7. The system according to claim 1, wherein: The control center includes: Control center management host; OPC server, used to obtain on-site operation data of each station equipment; A real-time server, used to collect the field operation data obtained by the OPC server in real time and upload it to the control center management host; The history server is used to manage and store the field operation data.
8. A virtual-reality fusion attack and defense drill method for an oil and gas production system, based on the virtual-reality fusion attack and defense drill system for an oil and gas production system according to any one of claims 1 to 7, characterized in that: include: Monitoring the network risk area of the oil and gas production system, and invoking attack strategy instructions to initiate the attack instructions on the communication links or control nodes in the network risk area; receiving the attack instruction, simulating the physical impact of the attack on the equipment in the field operation environment corresponding to the oil and gas production system; the field operation environment includes at least the oil transmission station, gas gathering station, refining station and gas transmission station, as well as the entire chain of production processes between them; Detect system anomalies of the station equipment, call the protection strategy matching the system anomaly for joint protection, and generate an attack and defense drill report.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which implements the steps of the method according to claim 8 when executed.
10. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the method according to claim 8 when executing the computer program.
Citation Information
Cited By
Attack and defense confrontation method and system based on chemical dynamic simulation
CN120997011A
An attack-defense confrontation method and system based on chemical engineering dynamic simulation
CN120997011B