Chaotic watermark-based network attack event traceability processing method and device, and medium
By collecting sensor data in the Industrial Internet of Things (IIoT), calculating uncertainty indicators and embedding chaotic encrypted watermarks, and monitoring execution result deviations in real time, the real-time and path correlation problems of network attack tracing in the IIoT are solved, enabling rapid location of attack sources and paths.
Patent Information
- Application Number
- CN202511333062.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-09-18
AI Technical Summary
Existing network attack attribution technologies lack real-time response capabilities in industrial IoT environments and are unable to model the transmission path correlation of attack behaviors in the physical-information fusion space.
It collects real-time data from industrial IoT sensors, calculates uncertainty indicators of device behavior, generates attack judgment flags and abnormal propagation paths, embeds chaotic encrypted watermarks in control commands, monitors execution result deviations through actuators, and generates attack source coordinate information and path maps.
It enables real-time dynamic quantitative evaluation of the behavior of industrial IoT devices, can quickly respond to attacks, ensure the physical executability of control commands, and locate tampered bits through watermark feedback data, thus solving the problem of missing correlation of physical layer attack transmission paths.
Smart Images

Figure CN120811802A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of industrial internet of things security technology, and in particular to a network attack event traceability processing method based on chaotic watermark, a device and a medium. BACKGROUND
[0002] Network attack traceability technology is a core research direction in the field of network security, and in recent years, progress has been made in both theory and practice. Existing traceability methods mainly rely on network traffic analysis, log record analysis and malicious code reverse engineering, etc. Attack features or behavior patterns are extracted to realize attack source positioning. For example, the IP address-based traceability technology traces the geographical location of the attacker through WHOIS query and Traceroute tool; the log analysis-based method identifies attack paths and constructs attack link graphs by analyzing system logs, security device logs and other data. In addition, with the integration of artificial intelligence and big data technology, machine learning algorithms are widely used in attack behavior pattern recognition and anomaly detection, which improves the traceability efficiency. In the industrial internet of things (IIoT) scenario, traceability technology is further combined with physical layer monitoring means to deal with the specific attack features in industrial control units (ICS).
[0003] Although the existing network attack traceability technology shows strong effectiveness in specific scenarios, its adaptability in the industrial internet of things environment still has limitations. First, the existing method relies on static log or traffic feature analysis, which is difficult to respond to dynamic attack behavior in real time. Second, the existing method lacks the ability to model the transmission path of attack behavior in the physical-information fusion space. SUMMARY
[0004] In view of the above existing problems, the present application is proposed.
[0005] Therefore, the present application provides a network attack event traceability processing method based on chaotic watermark to solve the problems of insufficient real-time response capability and missing physical layer attack transmission path association.
[0006] To solve the above technical problems, the present application provides the following technical solutions: In a first aspect, the present application provides a network attack event traceability processing method based on chaotic watermark, which comprises, Collecting real-time data generated by sensors in the industrial internet of things, the real-time data including timestamp, sensor ID, parameter type and parameter value; Calculating the uncertainty index of device behavior based on real-time data, and judging potential attack behavior to generate attack judgment flag and abnormal transmission path; According to the attack judgment flag and the abnormal transmission path, embedding chaotic encryption watermark in the control instruction sent to the actuator to obtain a control instruction stream carrying watermark; The executor responds to the control instruction stream carrying the watermark to complete the operation, and monitors the deviation value of the execution result from the expected physical behavior to generate the execution deviation value and the watermark feedback data; Attack source coordinate information is generated based on the execution deviation value and the watermark feedback data, and an attack path atlas is generated to push a traceability report.
[0007] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the uncertainty index of the real-time data computing device behavior is calculated as follows, The real-time data is divided into a plurality of independent data sequence groups; Based on the independent data sequence groups, the time window is calculated to obtain the conditional probability; According to the conditional probability, the conditional entropy value is calculated to obtain the uncertainty index of the device behavior.
[0008] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the uncertainty index of the real-time data computing device behavior is calculated as follows, According to the uncertainty index of the device behavior, the abnormal time window is marked; Based on the abnormal time window, the attack judgment flag is generated, and the abnormal conduction path is generated according to the attack judgment flag.
[0009] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the uncertainty index of the real-time data computing device behavior is calculated as follows, The control instruction sent to the executor is received; Based on the attack judgment flag, the chaotic watermark initial seed value and the hash value are generated; The chaotic watermark initial seed value and the hash value are subjected to XOR operation to generate the chaotic initial value, and the chaotic encryption watermark is generated through the Logistic chaotic mapping iteration formula; According to the abnormal conduction path, the perturbable field to be modified in the control instruction is determined; The chaotic encryption watermark is embedded in the perturbable field to obtain the control instruction stream carrying the watermark.
[0010] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the uncertainty index of the real-time data computing device behavior is calculated as follows, The executor parses the control instruction stream carrying the watermark, and performs the corresponding physical operation according to the parsing result; Real-time acquisition of physical output values in the process of performing physical operations to obtain execution results; Converting the control instruction stream carrying the watermark into a measurable physical quantity of the sensor to obtain the expected physical behavior.
[0011] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the execution deviation value and the watermark feedback data are generated, and the specific steps are as follows, The absolute value of the difference between the execution result and the expected physical behavior is taken as the deviation value, and the execution deviation value is generated based on the deviation value, the physical output value and the control instruction stream carrying the watermark; The watermark feedback data is generated according to the control instruction stream carrying the watermark.
[0012] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the attack source coordinate information is generated based on the execution deviation value and the watermark feedback data, and the attack path atlas is generated, and the traceability report is pushed, and the specific steps are as follows, The tampered bit is located based on the watermark feedback data, and the attack source coordinate information is generated according to the tampered bit and the attack judgment mark; The attack path atlas is generated according to the attack source coordinate information, and the traceability report is generated and pushed based on the tampered bit, the attack source coordinate information, the control instruction and the execution deviation value.
[0013] As a preferred scheme of the network attack event traceability processing method based on chaotic watermarking, the real-time data generated by the sensor in the industrial Internet of Things is collected, and the specific steps are as follows, A data collection agent is installed on the edge device of the industrial Internet of Things; The data collection agent is connected with the sensor of the industrial Internet of Things, and the original data stream is received in real time; The original data stream is converted into structured real-time data.
[0014] In a second aspect, the present application provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, any step of the network attack event traceability processing method based on chaotic watermarking according to the first aspect of the present application is realized.
[0015] In a third aspect, the present application provides a computer readable storage medium, which stores a computer program, and when the computer program is executed by the processor, any step of the network attack event traceability processing method based on chaotic watermarking according to the first aspect of the present application is realized.
[0016] The application has the beneficial effects that: by dividing the sensor real-time data into independent data sequence groups, dynamic quantitative evaluation of equipment behavior anomalies is realized, the information confusion degree of equipment behavior in a specific time window can be reflected, real-time response to the uncertainty change of equipment behavior can be realized, early warning is triggered when the attack behavior just causes physical consequences, and the deficiency of the prior art in real-time performance is solved; by embedding chaotic encryption watermark in the control instruction, it is difficult for the attacker to bypass the traceability detection by simply tampering with the control instruction, the physical executability of the control instruction is ensured, interference on the industrial process is avoided, even if the attacker disguises the IP address or uses a jump node, the tampering bit can still be located through the watermark feedback data, and the problem of missing association of the physical layer attack transmission path is solved. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0018] Fig. 1 Flowchart of the network attack event traceability processing method based on chaotic watermark.
[0019] Fig. 2 Schematic diagram for chaotic encryption watermark generation and embedding.
[0020] Fig. 3 Schematic diagram for generating execution deviation monitoring and watermark feedback.
[0021] Fig. 4 Schematic diagram for generating a traceability report. DETAILED DESCRIPTION
[0022] In order to make the above-mentioned purposes, features and advantages of the present application more apparent and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings of the specification.
[0023] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application, but the present application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the present application, therefore the present application is not limited to the specific embodiments disclosed below.
[0024] Second, the "one embodiment" or "an embodiment" referred to herein can include a particular feature, structure, or characteristic. The various embodiments appearing at different places in the specification are not necessarily all cumulative or alternative implementations of the application. In other words, the "in one embodiment" appearing at different places in the specification do not all refer to the same embodiment, nor are they mutually exclusive of other embodiments.
[0025] Referring to Figs. 1-4 For one embodiment of the present application, the embodiment provides a network attack event trace processing method based on chaotic watermark, comprising the following steps: S1: Collecting real-time data generated by sensors in industrial Internet of Things, the real-time data including timestamp, sensor ID, parameter type and parameter value.
[0026] The specific steps are as follows, S1.1 Installing a data collection agent on the edge device of industrial Internet of Things, the data collection agent being realized based on an open source framework and used for managing sensor data flow.
[0027] In specific operation, a cross-compilation tool chain corresponding to the edge device of industrial Internet of Things is used to compile the source code of the open source framework, to generate an executable file suitable for the edge device of industrial Internet of Things; the compiled executable file is transmitted to a designated storage directory of the edge device of industrial Internet of Things through a secure file transfer protocol; A configuration file of the data collection agent is created on the edge device of industrial Internet of Things, the configuration file setting a port number listened to by the data collection agent and an address list of industrial Internet of Things sensors; the executable file is added with execution authority in the operating environment of the edge device of industrial Internet of Things; a start command is executed to run the data collection agent, and the data collection agent loads the configuration file to start listening to the specified port.
[0028] S1.2 Connecting the data collection agent with the industrial Internet of Things sensors through a physical interface, configuring communication parameters, and ensuring that the two-way communication is ready.
[0029] S1.3 Subscribing to a sensor data topic through a message queue telemetry transfer protocol to receive a raw data stream in real time.
[0030] Further, the address of the message queue telemetry transfer agent server is set in the configuration file of the data collection agent; the message topic section of the configuration file is modified, and a data topic path corresponding to the industrial Internet of Things sensors is added, each path corresponding to a unique industrial Internet of Things sensor identifier; The data collection agent sends a subscription message to the message queue telemetry transfer agent server, and the message queue telemetry transfer agent server forwards the corresponding industrial Internet of Things sensor data to the data collection agent, forming a raw data stream.
[0031] S1.4 Extract the timestamp, sensor ID, parameter type, and parameter value in the original data stream, and convert them into structured real-time data.
[0032] Specifically, the timestamp, sensor ID, parameter type, and parameter value are combined into a comma-separated value format record to form structured real-time data.
[0033] It should be noted that collecting real-time data generated by sensors in industrial Internet of Things helps to ensure the comprehensiveness and real-time nature of data collection, providing a foundation for subsequent analysis; by installing data collection agents on the edge devices of industrial Internet of Things to manage sensor data streams, unified monitoring of sensor data in industrial Internet of Things is achieved, avoiding data omission or delay problems; using the message queue telemetry transport protocol to subscribe to sensor data topics ensures stable reception of data streams and reduces the risk of communication interruption; extracting the timestamp, sensor ID, parameter type, and parameter value and converting them into structured real-time data ensures the standardization of data format, facilitating subsequent processing; step S1 improves the reliability of the entire traceability process, as complete and accurate real-time data is a prerequisite for detecting potential attack behavior; real-time collection of sensor data in industrial Internet of Things also supports rapid response to changes in industrial environment, enhancing the overall resilience of industrial Internet of Things systems when facing network threats; connecting industrial Internet of Things sensors through physical interfaces and configuring communication parameters ensures the robustness of bidirectional communication, preventing data from being tampered with or lost during transmission; structured real-time data lays a solid data foundation for uncertainty index calculation, optimizing the accuracy of attack behavior judgment.
[0034] S2: Calculate the uncertainty index of device behavior based on real-time data, and judge potential attack behavior to generate attack judgment flag and abnormal conduction path.
[0035] The specific steps are as follows, S2.1 Group real-time data by sensor ID and parameter type to form independent data sequence groups, each group containing parameter values of the same sensor and parameter type.
[0036] S2.2 Set a fixed time window covering real-time data within a range of consecutive timestamps, and slide the time window forward by a fixed step.
[0037] S2.3 For real-time data within the time window, calculate the parameter value distribution histogram, calculate the conditional probability of parameter values in the current window and the previous window, calculate the conditional entropy value based on the conditional probability, and obtain the uncertainty index of device behavior.
[0038] Further, from the real-time data within the time window, extract the parameter value, divide the value range of the parameter value into multiple equal-width intervals, count the number of parameter values appearing in each interval, and form a parameter value distribution histogram; The ratio of the number of occurrences of the parameter value corresponding to the interval to the total number of occurrences of the parameter value in the current time window is taken as the current window interval probability; the ratio of the number of occurrences of the parameter value corresponding to the interval to the total number of occurrences of the parameter value in the previous time window is taken as the previous window interval probability; and the ratio of the current window interval probability to the previous window interval probability is taken as the conditional probability value; The expression for calculating the conditional entropy value based on the conditional probability is: ; wherein, is the conditional entropy value, indicating the degree of uncertainty of the parameter value distribution of the current time window relative to the parameter value distribution of the previous time window, is the interval index, is the total number of intervals, is the conditional probability value of the i-th interval of the previous time window, is the conditional probability value of the i-th interval of the current time window.
[0039] S2.4 Set the upper threshold value based on the historical conditional entropy value using the percentile method, for example, sort the historical conditional entropy values in ascending order, and take the 95% percentile of the historical conditional entropy values as the upper threshold value; if the conditional entropy value exceeds the upper threshold value, mark the corresponding time window as an abnormal window.
[0040] S2.5 Create an attack judgment flag record for each abnormal window, including the time window start timestamp, sensor ID, parameter type, conditional entropy value, upper threshold value, and flag state.
[0041] It should be noted that the time window start timestamp is the first time point of the abnormal window; and the flag state is fixed as the string "abnormal".
[0042] S2.6 Scan the attack judgment flag record, sort the abnormal sensor IDs, connection device IDs, and connection device types of the adjacent sensors existing in the abnormal window in topological order, and simultaneously merge to form an abnormal conduction path.
[0043] It should be noted that: the uncertainty index based on real-time data computing device behavior is beneficial to identify abnormal patterns in advance, and enhances the detection accuracy of potential attack behavior; grouping real-time data according to sensor ID and parameter type forms independent data sequence groups, allowing for fine-grained analysis of specific industrial Internet of Things devices, avoiding misjudgment caused by mixed data; using a time window to statistically analyze the independent data sequence group and calculate the uncertainty index can capture the dynamic changes of device behavior, such as quantifying uncertainty through conditional entropy, thereby discovering abnormalities that deviate from normal behavior at an early stage; setting an upper threshold and marking abnormal time windows improves the objectivity of the judgment and reduces subjective interference; generating attack judgment flag records containing time window start timestamp, sensor ID and parameter type provides a clear attack event evidence chain; scanning attack judgment flag records to generate abnormal conduction paths, and sorting abnormal sensor IDs and connected device IDs reveals the propagation path of the attack in the industrial Internet of Things topology; step S2 is beneficial to quickly locate the potential attack source, shorten the response time, and generate structured output for subsequent watermark embedding; the construction of the abnormal conduction path strengthens the visualization of the attack behavior, making it easier for security personnel to understand the threat propagation mechanism and improving the overall protection capability of the industrial Internet of Things; the calculation process of the uncertainty index also optimizes resource utilization and avoids the inefficiency of full data analysis.
[0044] S3: embedding chaotic encryption watermark in the control instruction sent to the actuator according to the attack judgment flag and the abnormal conduction path, to obtain a control instruction stream carrying the watermark.
[0045] The specific steps are as follows, S3.1 convert the time window start timestamp into Unix millisecond timestamp format as the initial seed value of the chaotic watermark; convert the sensor ID into a hash value through the SHA-256 hash algorithm; take the fixed bit bytes of the hash value and the initial seed value of the chaotic watermark to perform XOR operation to generate the chaotic initial value; generate the chaotic encryption watermark through the Logistic chaotic mapping iteration formula.
[0046] In specific operation, the control instruction sent from the controller of the industrial Internet of Things to the actuator is received, and the time window start timestamp in the attack judgment flag record is extracted; the time window start timestamp is converted into a millisecond-level integer value format starting from the Unix epoch time as the initial seed value of the chaotic watermark; The sensor ID is used as input to generate a fixed-length binary hash value using the SHA-256 hash algorithm; From the left start position of the hash value, extract consecutive fixed number of bytes to form a binary fragment; bitwise XOR operation is performed between the chaotic watermark initial seed value and the binary segment: a logical judgment is performed on each bit of the chaotic watermark initial seed value and the binary segment, if the values of the two bits at the same position are equal, 0 is output, if the values of the two bits at the same position are not equal, 1 is output; after all logical judgments are completed, the chaotic initial value is generated; The chaotic initial value is converted into a floating-point number format, the floating-point number is linearly mapped to the interval (0, 1) to obtain a normalized chaotic initial value, and the input range requirement of the Logistic chaotic mapping is ensured; The normalized chaotic initial value is input into the Logistic chaotic mapping standard iteration formula, the first iteration value is output, the first iteration value is input into the Logistic chaotic mapping standard iteration formula, a new iteration value is output, and the new iteration value is taken as the input of the Logistic chaotic mapping standard iteration formula, and the same iteration calculation is repeatedly executed; For the iteration value output for each iteration, the mantissa part of the iteration value is extracted, the mantissa part is converted into a fixed-length binary string, the middle fixed bit segment of the binary string is intercepted to obtain a binary bit segment, and the sign bit interference is avoided; the mantissa part is the decimal part of the iteration value. All binary bit segments are connected in the iteration order, the iteration is stopped when the fixed multiple of the length of the control instruction bit number is reached, and the chaotic encryption watermark is generated.
[0047] S3.2. According to the parameter type, the type of the control instruction to be modified is determined, and the perturbable field in the control instruction is located; the chaotic encryption watermark is divided into independent watermark bits by bit, and each independent watermark bit corresponds to a perturbable field; the perturbable field of the control instruction is modified according to the independent watermark bit, and a watermark header identifier is added, to form a control instruction stream carrying a watermark.
[0048] Further, the historical parameter type not attacked and the corresponding control instruction type are integrated into an industrial protocol mapping table; the parameter type is read in the attack judgment flag record, and the control instruction type corresponding to the parameter type is obtained by querying the industrial protocol mapping table; According to the control instruction type, the perturbable field in the control instruction is located, for example, when the control instruction type is a PID control instruction, the mantissa field with a fixed number of bits is located and marked as a perturbable field, when the control instruction type is an analog output instruction, the significant digit field with a fixed number of bits is located and marked as a perturbable field, and when the control instruction type is a Boolean control instruction, the state byte reserved bit is located and marked as a perturbable field; For each bit value of the perturbable field, if the independent watermark bit value is 1, the bit value of the current perturbable field is flipped, if the independent watermark bit value is 0, the bit value of the current perturbable field is kept unchanged, to obtain the modified control instruction; the protocol reserved bit of the modified control instruction is embedded with a fixed number of identifiers to obtain the control instruction stream carrying the watermark, and the identifier is a binary sequence.
[0049] It should be noted that: embedding the chaotic encryption watermark in the control instruction according to the attack judgment flag and the abnormal conduction path is beneficial to enhance the anti-tampering property and traceability of the instruction stream; generating the chaotic initial value based on the time window start timestamp in the attack judgment flag and the sensor ID ensures the uniqueness and unpredictability of the watermark, preventing attackers from forging or copying; iteratively generating the chaotic encryption watermark utilizes the dynamic characteristics of chaotic mapping, making the watermark highly random and improving the resistance to malicious interference; determining the perturbable field to be modified in the control instruction according to the parameter type in the abnormal conduction path, and selecting the embedding position, such as the mantissa field of the PID control instruction or the significant digit field of the analog output instruction, realizes the seamless integration of the watermark and the instruction content; embedding the chaotic encryption watermark in the perturbable field to obtain the control instruction stream carrying the watermark provides an additional security layer, as any tampering attempt will cause the watermark feature to change, facilitating subsequent verification; step S3 is beneficial to maintaining the integrity of the instruction and ensuring that the instructions received by the executor come from a trusted source; the embedding of the chaotic encryption watermark also supports real-time monitoring, as it forms a closed loop with the watermark feedback data, laying the foundation for attack source coordinate information generation; the control instruction stream carrying the watermark simplifies the communication management in the industrial Internet of Things, reducing the risk of physical operation deviation caused by tampered instructions; the addition of the watermark header identification improves the identification efficiency of the instructions and optimizes the efficiency of the entire traceability process.
[0050] S4: The executor completes the operation in response to the control instruction stream carrying the watermark, and simultaneously monitors the deviation value of the execution result from the expected physical behavior to generate the execution deviation value and the watermark feedback data.
[0051] The specific steps are as follows, S4.1 The executor sequentially receives the control instruction stream carrying the watermark, parses the instruction content of the control instruction stream carrying the watermark, and executes the physical operation according to the instruction content.
[0052] Specifically, the executor receives the control instruction stream carrying the watermark in real time through the industrial Ethernet interface, stores the data packets into a ring buffer, and reorganizes the continuous instruction sequence according to the protocol frame sequence number; extracts the encrypted field from the continuous instruction sequence, decrypts the encrypted field using the key, and obtains the instruction content; Using instruction content to drive physical devices to perform physical operations, for example, inputting the speed set value in the instruction content into the servo driver, adjusting the rotor position using closed-loop control, sending the opening percentage in the instruction content to the positioner, the pneumatic actuator pushing the valve core to the opening percentage position, writing the Boolean state in the instruction content to the relay coil, closing / opening the main circuit contact.
[0053] S4.2 Collecting physical output values in real time during the execution of physical operations to obtain execution results; extracting the expected value field from the control instruction and converting it into a measurable physical quantity of the sensor to obtain the expected physical behavior; taking the absolute value of the difference between the execution result and the expected physical behavior as the deviation value.
[0054] It should be noted that during the execution of physical operations, physical output values are collected in real time, for example, in motor operation, the actual rotor speed is captured using a laser speedometer, in valve operation, the real-time flow in the pipeline is recorded using a pressure transmitter, and in switch operation, the circuit working current is monitored using a current transformer. Each collection generates a physical output value record with a millisecond-level timestamp; Extracting the expected value field from the control instruction stream carrying the watermark, for example, for PID control instructions, reading the speed set value in the set value register, reading the range coefficient and opening percentage from the analog output instruction, and for Boolean instructions, reading the binary bit value of the state register; Converting the expected value field into a measurable physical quantity of the sensor, for example, taking the speed set value as the expected speed value, taking the product of the range coefficient and the opening percentage as the expected flow value, and if the binary bit value is 1, taking the rated working current as the expected current value, and if the binary bit value is 0, setting the expected current value to 0.
[0055] S4.3 Extracting the identifier and the perturbable field from the control instruction stream carrying the watermark, verifying whether the identifier is consistent with the identifier embedded in S3.2, if not, marking it as an abnormal identifier, stopping the physical operation of the current control instruction execution, and locking the executor operation permission; Recording the binary sequence of the abnormal identifier, the timestamp of stopping the physical operation of the current control instruction execution, the binary sequence of the abnormal identifier, and the control instruction type as an attack feature label; Regenerating the identifier and sending a watermark verification instruction to the executor to re-verify the identifier.
[0056] It should be noted that the identifier and the identifier embedded in S3.2 are completely identical in all bit values, and the identifier and the identifier embedded in S3.2 are consistent, and if any bit value is different, the identifier and the identifier embedded in S3.2 are inconsistent.
[0057] S4.4 If the identifier is consistent with the identifier embedded in S3.2, record the deviation value, the timestamp of collecting the physical output value, the control instruction as the execution deviation value, and record the identifier and the perturbable field as the watermark feedback data.
[0058] It should be noted that: the actuator responds to the control instruction stream carrying the watermark to complete the operation, which is beneficial to verify the accuracy of the physical behavior in real time, and generate feedback data to strengthen the traceability; parsing the control instruction stream carrying the watermark and executing the corresponding physical operation according to the parsing result ensures that the instruction is correctly interpreted and executed, for example, driving the servo driver to adjust the rotor position or controlling the pneumatic actuator to push the valve core, which improves the operation reliability. Real-time collection of the actual physical output value of the physical operation obtains the execution result, which provides an objective physical state record for comparison with the expected value; extracting the expected value field from the control instruction stream and converting it into a physical quantity measurable by a sensor to obtain the expected physical behavior, which ensures the accuracy of the comparison benchmark and avoids misjudgment; calculating the absolute value of the difference between the execution result and the expected physical behavior to generate the execution deviation value, which quantifies the operation deviation and helps to identify potential attack effects; extracting the watermark identifier and the perturbable field from the control instruction stream to generate the watermark feedback data, which provides watermark state information and prepares input for subsequent validity verification; step S4 is beneficial to quickly detect abnormal operation, because the execution deviation value and the watermark feedback data directly reflect the attack consequences; the generation of the watermark feedback data also promotes closed-loop control and supports real-time verification of chaotic encryption watermark; the deviation monitoring during the operation of the actuator optimizes the response speed, and the generation of the execution deviation value and the watermark feedback data is beneficial to reduce false positives and improve credibility through matching of the physical behavior and the actual output; step S4 strengthens the resilience of the industrial Internet of Things and ensures that the physical operation is consistent with the control instruction.
[0059] S5: Based on the execution deviation value and the watermark feedback data, generate attack source coordinate information and attack path atlas, and push a traceability report.
[0060] The specific steps are as follows, S5.1 Input the normalized chaotic initial value in step S3.1 into the Logistic chaotic mapping standard iteration formula to generate a chaotic sequence; extract the perturbable field in the control instruction, calculate the Hamming distance between the perturbable field and the corresponding bit value in the chaotic sequence, and if the Hamming distance does not exceed a fixed proportion of the total number of bits, mark it as valid watermark, and if the Hamming distance exceeds a fixed proportion of the total number of bits, mark it as a tampered bit.
[0061] Further, the Hamming distance between the perturbable field and the corresponding bit value in the chaotic sequence is calculated: the perturbable field and the corresponding bit value in the chaotic sequence are compared bit by bit, and the index position where the same index bit value is not equal is taken as a difference bit, and the Hamming distance is the number of difference bits.
[0062] S5.2 associates the identifier corresponding timestamp with the time window start timestamp in S2.5; based on the tamper bit, the controlled device register address is located to obtain the attacked device number, and the position corresponding to the attacked device number is taken as the attack source coordinate information.
[0063] It should be noted that if the difference between the identifier corresponding timestamp and the time window start timestamp does not exceed the fixed time, it is determined as the same event time point.
[0064] S5.3 constructs the connection relationship between the devices into a device topology graph; the node corresponding to the attacked device number in the device topology graph is represented by a red node; from the abnormal conduction path in S2.6, the devices connected with the attack device number are extracted, and the corresponding nodes are represented by yellow nodes.
[0065] In specific operation, the connection relationship and connection direction between the devices are collected, each device is taken as a node, the nodes are connected according to the connection relationship and connection direction between the devices, and the node is a green node by default.
[0066] S5.4 reads the attack source coordinate from the attack source coordinate information, takes the ratio of the number of tamper bits to the number of disturbable field bits as the tamper bit proportion, defines the control instruction type and the tamper bit proportion as the attack type, takes the maximum deviation value recorded in the execution deviation value as the maximum physical deviation; and merges the attack source coordinate, the attack type, the maximum physical deviation and the device topology graph into a traceability report.
[0067] It should be noted that: based on the execution deviation value and the watermark feedback data to generate the attack source coordinate information is beneficial to accurately locate the attack source and optimize the response mechanism; verifying the effectiveness of the chaotic encryption watermark in the watermark feedback data and locating the tampered bit confirms the watermark integrity, which facilitates the differentiation between normal operation and attack interference; generating the attack source coordinate information according to the timestamp association relationship between the tampered bit and the attack judgment flag; based on the attack source coordinate information and the device topology graph, marking the attacked device node and generating the attack path graph, visualizing the attack diffusion path, for example, using red nodes to represent the attacked device number nodes and yellow nodes to represent the connected device nodes, enhancing the understandability of the threat; merging the attack source coordinate information, the attack type, the maximum physical deviation and the attack path graph into the traceability report, integrating the key information, and facilitating comprehensive analysis of the attack event; pushing the traceability report to the security monitoring terminal, realizing the instant delivery of information, and supporting rapid decision-making; step S5 is beneficial to shorten the traceability time, because the attack source coordinate information and the attack path graph are directly derived from the execution deviation value and the watermark feedback data, reducing the need for manual intervention; the generation of the attack path graph also optimizes the security audit of the industrial Internet of Things, because it is based on the device topology graph, ensuring the accuracy of the path; pushing the traceability report is beneficial to collaborative response and improves the overall security level; the process of generating the attack source coordinate information strengthens the traceability of attack behavior and reduces the risk of similar events in the future; merging the traceability report provides a unified output, facilitating the storage and analysis of historical attack events.
[0068] The embodiment also provides a computer device suitable for the network attack event traceability processing method based on chaotic watermark, which comprises a memory and a processor.
[0069] The computer device can be a terminal, which comprises a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device comprises a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, operator network, NFC (near field communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device. In addition, an external keyboard, touchpad or mouse can also be used.
[0070] The embodiment also provides a storage medium on which a computer program is stored, the program being executed by a processor to implement a method for tracing a network attack event based on chaotic watermarking proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk.
[0071] To sum up, the present application achieves dynamic quantitative evaluation of equipment behavior anomaly by dividing sensor real-time data into independent data sequence groups, can reflect the information confusion degree of equipment behavior in a specific time window, can respond to the uncertainty change of equipment behavior in real time, triggers early warning when the attack behavior just causes physical consequences, and solves the deficiency of real-time performance of the prior art; by embedding chaotic encryption watermark in the control instruction, it is difficult for the attacker to bypass the traceability detection by simply tampering with the control instruction, ensures the physical executability of the control instruction, avoids interference to the industrial process, even if the attacker disguises the IP address or uses a jump node, the tampered bit can still be located through the watermark feedback data, and the problem of missing association of the physical layer attack transmission path is solved.
[0072] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application, although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and all of them should be covered in the scope of the claims of the present application.
Claims
1. A method for tracing the source of network attack events based on chaotic watermarking, characterized by: include, Collect real-time data generated by sensors in the industrial Internet of Things, including timestamps, sensor IDs, parameter types, and parameter values; Calculate uncertainty indicators of device behavior based on real-time data, identify potential attack behaviors, and generate attack detection signs and abnormal transmission paths; According to the attack judgment mark and abnormal conduction path, a chaotic encryption watermark is embedded in the control instruction sent to the actuator to obtain a control instruction stream carrying the watermark; The executor receives the control instruction stream carrying the watermark, executes the physical operation and obtains the execution result. At the same time, it monitors the deviation between the execution result and the expected physical behavior, and generates the execution deviation value and watermark feedback data. Generate attack source coordinate information based on execution deviation value and watermark feedback data, generate attack path map, and push tracing report.
2. The method for tracing the source of network attack events based on chaotic watermarking according to claim 1, characterized in that: The specific steps of calculating the uncertainty index of device behavior based on real-time data are as follows: Divide real-time data into multiple independent data series groups; Based on the independent data series group, the conditional probability is calculated using a time window; The conditional entropy value is calculated based on the conditional probability to obtain the uncertainty index of the device behavior.
3. The method for tracing the source of network attack events based on chaotic watermarking according to claim 1, characterized in that: The specific steps of judging potential attack behaviors and generating attack determination marks and abnormal conduction paths are as follows: Mark abnormal time windows based on uncertainty indicators of device behavior; An attack determination flag is generated based on the abnormal time window, and an abnormal conduction path is generated according to the attack determination flag.
4. The method for tracing the source of network attack events based on chaotic watermarking according to claim 1, characterized in that: The chaotic encryption watermark is embedded in the control instruction sent to the actuator to obtain the control instruction stream carrying the watermark. The specific steps are as follows: Receive control instructions sent to the actuator; Generate the initial seed value and hash value of the chaotic watermark based on the attack judgment mark; Perform XOR operation on the initial seed value of the chaotic watermark and the hash value to generate the chaotic initial value, and then generate the chaotic encrypted watermark through the Logistic chaotic mapping iterative formula; determining a perturbable field to be modified in the control instruction according to the abnormal conduction path; The chaotic encrypted watermark is embedded into the perturbed field to obtain the control instruction stream carrying the watermark.
5. The method for tracing the source of network attack events based on chaotic watermarking according to claim 1 is characterized in that: The executor receives the control instruction stream carrying the watermark, performs the physical operation and obtains the execution result, while monitoring the deviation between the execution result and the expected physical behavior. The specific steps are as follows: The executor parses the control instruction stream carrying the watermark and performs the corresponding physical operation based on the parsing results; Real-time collection of physical output values during physical operation to obtain execution results; The control instruction stream carrying the watermark is converted into physical quantities measurable by sensors to obtain the expected physical behavior.
6. The method for tracing the source of network attack events based on chaotic watermarking according to claim 5 is characterized in that: The specific steps of generating the execution deviation value and watermark feedback data are as follows: The absolute value of the difference between the execution result and the expected physical behavior is used as the deviation value, and the execution deviation value is generated based on the deviation value, the physical output value and the control instruction stream carrying the watermark; Generate watermark feedback data according to the control instruction stream carrying the watermark.
7. The method for tracing the source of network attack events based on chaotic watermarking according to claim 1, characterized in that: The attack source coordinate information is generated based on the execution deviation value and watermark feedback data, and the attack path map is generated and the traceability report is pushed. The specific steps are as follows: Locate the tampered bit based on the watermark feedback data, and generate the attack source coordinate information based on the tampered bit and the attack judgment flag; Generate an attack path map based on the attack source coordinate information, and generate and push a traceability report based on the tampered bit, attack source coordinate information, control instructions, and execution deviation values.
8. The method for tracing the source of network attack events based on chaotic watermarking according to claim 1, characterized in that: The specific steps for collecting real-time data generated by sensors in the industrial Internet of Things are as follows: Install data collection agents on edge devices in the Industrial Internet of Things; Connect data collection agents to industrial IoT sensors and receive raw data streams in real time; Convert raw data streams into structured real-time data.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network attack event tracing method based on chaotic watermarking according to any one of claims 1 to 8 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network attack event tracing method based on chaotic watermarking according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Abnormality sensing and tracking method and system
CN107046535A
Data stream tracing method, device and equipment and storage medium
CN116915519A
Attack detection method and system based on chaotic mapping and transformation of credential
CN119995932A
System for providing a real-time attacking connection traceback using a packet watermark insertion technique and method therefor
US20040049695A1