An industrial equipment runtime electromagnetic fingerprint real-time monitoring and anomaly identification system

By constructing a dynamic electromagnetic fingerprint feature model through denoising and feature extraction, the problem of easy replication of electromagnetic fingerprints in existing technologies is solved, and more accurate and secure real-time monitoring and anomaly identification of electromagnetic fingerprints are achieved.

CN120832623BActive Publication Date: 2025-12-09MILITARY SECRECY QUALIFICATION EXAMINATION & CERTIFICATION CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511320245.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-12-09
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

In existing technologies, electromagnetic fingerprints are easily copied, which poses a risk of replay attacks on devices. Existing technologies also make it difficult to achieve accurate real-time monitoring and anomaly identification.

Method used

The noise points in the electromagnetic signal curve are removed by the data denoising module, the periodic features of the denoised electromagnetic signal curve are extracted, a dynamic electromagnetic fingerprint feature model is constructed, and the electromagnetic fingerprint anomalies of the device are monitored in real time by the feature difference analysis module and the anomaly monitoring module. The dynamic electromagnetic fingerprint feature difference sequence and anomaly degree are obtained by using STL time series decomposition and Fourier transform techniques.

Benefits of technology

It achieves more accurate and secure electromagnetic fingerprint recognition, avoids the attack risk of static electromagnetic fingerprints being copied, and improves the accuracy and security of anomaly recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832623B_ABST
    Figure CN120832623B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of electromagnetic fingerprint analysis, in particular to a real-time monitoring and abnormality identification system for electromagnetic fingerprints of industrial equipment in operation. The system comprises a data denoising module, which is used for obtaining an electromagnetic signal curve of a target equipment and performing denoising to obtain a denoised electromagnetic signal curve; a feature extraction module, which is used for obtaining a first feature, a second feature and a third feature of a period according to the mean value, the maximum peak value and the slope between every two adjacent data of the data of the period; a feature difference analysis module, which is used for obtaining a first feature difference sequence, a second feature difference sequence and a third feature difference sequence; and an abnormality monitoring module, which is used for obtaining residual terms of the first, second and third feature difference sequences respectively, and judging whether the current electromagnetic fingerprint is abnormal according to the last residual point and other residual points except the last residual point in the residual terms. The application can accurately detect whether the electromagnetic fingerprint is abnormal.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of electromagnetic fingerprint analysis, and particularly relates to an industrial equipment runtime electromagnetic fingerprint real-time monitoring and abnormality identification system. BACKGROUND

[0002] An electromagnetic fingerprint is a kind of identification "fingerprint" formed based on the unique electromagnetic radiation characteristics generated by an electronic device in the working process. Just like a person's fingerprint, each electronic device will generate unique electromagnetic emission signals in a specific frequency band and time sequence due to factors such as circuit design, component differences, power characteristics, and working frequency when running, and these signals have identifiable and stable characteristics, which are called the "electromagnetic fingerprint" of the electronic device.

[0003] The prior art can generally extract mean, variance, kurtosis and other characteristics that can distinguish different devices from the device running data to obtain the electromagnetic fingerprint corresponding to the device. However, the electromagnetic characteristics of the prior art are generally obtained based on the static characteristics of the device running data, and are easy to be copied by static fingerprints to cause the device to be replayed. SUMMARY

[0004] In order to solve the above technical problems, the purpose of the present application is to provide an industrial equipment runtime electromagnetic fingerprint real-time monitoring and abnormality identification system, and the technical solution adopted is as follows:

[0005] One embodiment of the present application provides an industrial equipment runtime electromagnetic fingerprint real-time monitoring and abnormality identification system, which comprises:

[0006] A data denoising module is configured to obtain an electromagnetic signal curve of a target device, obtain noise points in the electromagnetic signal curve according to each residual point in a residual term corresponding to the electromagnetic signal curve and residual points adjacent to each residual point, and obtain a denoised electromagnetic signal curve by replacing values of the noise points in the electromagnetic signal curve.

[0007] A feature extraction module is configured to obtain a period of the denoised electromagnetic signal curve, and obtain a first feature, a second feature and a third feature of the period according to a mean value of data points in the period, a maximum peak value of the data points and a slope between each two adjacent data points in the denoised electromagnetic signal curve, respectively.

[0008] A feature difference analysis module is configured to obtain a first feature difference sequence, a second feature difference sequence and a third feature difference sequence according to differences between the first features of each two adjacent periods, differences between the second features and differences between the third features, respectively.

[0009] An anomaly monitoring module is configured to obtain residual terms of the first, second and third feature difference sequences respectively, denoted as a first residual term, a second residual term and a third residual term respectively; and determine whether the current electromagnetic fingerprint is abnormal according to a last residual point and other residual points except the last residual point in the first residual term, the second residual term and the third residual term.

[0010] Preferably, the electromagnetic signal curve of the target device is obtained, including:

[0011] The collected electromagnetic signal data is projected into a two-dimensional rectangular coordinate system to obtain an electromagnetic signal curve, and a coordinate horizontal axis of the electromagnetic signal curve is a collection time sequence, and a coordinate vertical axis is an electromagnetic signal intensity of the target device.

[0012] Preferably, the noise point in the electromagnetic signal curve is obtained according to each residual point in the residual term corresponding to the electromagnetic signal curve and adjacent residual points of each residual point, including:

[0013] A residual value of a residual point in the residual term corresponding to the electromagnetic signal curve is obtained, and a difference absolute value between the residual value of the residual point and a mean value of residual values of all residual points in the residual term is normalized to obtain an overall difference of the residual point; a sum of difference absolute values between the residual value of the residual point and residual values of adjacent residual points before and after the residual point is normalized to obtain a neighborhood distance of the residual point; the overall difference and the neighborhood distance of the residual point are added and averaged to obtain a noise point abnormality degree of the residual point; and if the noise point abnormality degree of the residual point is greater than or equal to a first preset threshold, a data point on the electromagnetic signal curve corresponding to the residual point is a noise point.

[0014] Preferably, the period of the denoised electromagnetic signal curve is obtained, including:

[0015] STL time sequence decomposition is used on the data points of the denoised electromagnetic signal curve to obtain a seasonal term, and Fourier transform is performed on time domain data in the seasonal term to obtain frequency domain data; a frequency corresponding to a maximum peak point in the frequency domain data is obtained, denoted as a main frequency; an inverse of the main frequency is obtained to obtain the period of the denoised electromagnetic signal curve.

[0016] Preferably, the first feature, the second feature and the third feature of a period of the denoised electromagnetic signal curve are obtained according to a mean value of data points of the period, a maximum peak value and a slope between each two adjacent data points, respectively, including:

[0017] The mean value of the data points in a period and the maximum peak value are respectively taken as the first feature and the second feature of the period; eight slope intervals are obtained by uniformly dividing the 180-degree range, and each slope interval corresponds to a chain code value; the chain code value corresponding to the slope between each two adjacent data points in the period is determined based on the slope interval to which the slope between the two data points belongs, and the chain code values are sorted according to the arrangement order of the data points in the period to obtain the chain code sequence corresponding to the period, which is recorded as the third feature of the period.

[0018] Preferably, the first feature difference sequence, the second feature difference sequence and the third feature difference sequence are obtained according to the differences between the first features, the differences between the second features and the differences between the third features of each two adjacent periods, respectively, including:

[0019] The absolute value of the difference between the mean values of the data points of the two adjacent periods is taken as the first feature difference of the two adjacent periods; the absolute value of the difference between the maximum peak values of the data points of the two adjacent periods is taken as the second feature difference of the two adjacent periods; the mean value of the absolute values of the differences between the corresponding chain code values in the chain code sequences of the two adjacent periods is taken as the third feature difference of the two adjacent periods; the first feature differences, the second feature differences and the third feature differences of each two adjacent periods in the denoising electromagnetic signal curve are arranged in time sequence to obtain the first feature difference sequence, the second feature difference sequence and the third feature difference sequence.

[0020] Preferably, the residual terms of the first, second and third feature difference sequences are obtained, respectively, including:

[0021] The first, second and third feature difference sequences are subjected to STL time series decomposition, respectively, to obtain the residual terms of the first, second and third feature difference sequences.

[0022] Preferably, whether the current electromagnetic fingerprint is abnormal is judged according to the last residual point and the other residual points in the first residual term, the second residual term and the third residual term, including:

[0023] The absolute value of the difference between the residual value of the last residual point in the first residual term and the average of the residual values of the other residual points in the first residual term is obtained, and is normalized to obtain a first residual deviation degree; the absolute value of the difference between the residual value of the last residual point in the second residual term and the average of the residual values of the other residual points in the second residual term is obtained, and is normalized to obtain a second residual deviation degree; the absolute value of the difference between the residual value of the last residual point in the third residual term and the average of the residual values of the other residual points in the third residual term is obtained, and is normalized to obtain a third residual deviation degree; the average of the first residual deviation degree, the second residual deviation degree and the third residual deviation degree is obtained to obtain a current abnormality degree; if the current abnormality degree is greater than a second preset threshold, the current electromagnetic fingerprint is abnormal.

[0024] The embodiments of the present application have at least the following beneficial effects: the electromagnetic signal curve of the target device is obtained, then the noise points in the electromagnetic signal curve are obtained according to each residual point in the residual term corresponding to the electromagnetic signal curve and the residual points adjacent to each residual point, and then the value of the noise points in the electromagnetic signal curve is replaced to obtain a denoising electromagnetic signal curve, which can remove the noise points in the electromagnetic signal curve, so that the subsequent analysis is more accurate; further, the period of the denoising electromagnetic signal curve is obtained, the features of the data points in one period of the denoising electromagnetic signal curve are extracted to obtain the first feature, the second feature and the third feature of the period, a dynamic electromagnetic fingerprint (the first feature, the second feature and the third feature) is constructed based on the period division, then the first feature difference sequence, the second feature difference sequence and the third feature difference sequence are obtained based on the differences between the first features of each two adjacent periods, the differences between the second features and the differences between the third features, the residual terms of the first, second and third feature difference sequences are obtained respectively, and whether the current electromagnetic fingerprint is abnormal is judged according to the last residual point and the other residual points except the last residual point in the residual term, which avoids the defects of the static electromagnetic fingerprint and obtains more accurate and safer device electromagnetic fingerprint identification results. BRIEF DESCRIPTION OF DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, and the advantages thereof, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.

[0026] Figure 1 A system block diagram of an industrial equipment runtime electromagnetic fingerprint real-time monitoring and abnormality identification system provided by the embodiments of the present application;

[0027] Figure 2 The code value conversion schematic diagram of the industrial equipment runtime electromagnetic fingerprint real-time monitoring and anomaly identification system provided by the embodiment of the present application is provided. DETAILED DESCRIPTION

[0028] In order to further illustrate the technical means and effects taken by the present application to achieve the predetermined object of the application, the specific implementation, structure, features and effects of the industrial equipment runtime electromagnetic fingerprint real-time monitoring and anomaly identification system according to the present application are described in detail as follows in combination with the drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs.

[0030] The specific scheme of the industrial equipment runtime electromagnetic fingerprint real-time monitoring and anomaly identification system provided by the present application is specifically described below in combination with the drawings.

[0031] Embodiment:

[0032] The main application scenario of the present application is: when the electromagnetic fingerprint of the industrial equipment is monitored in real time, the static electromagnetic fingerprint is easy to be identified and copied, and there is a risk of being attacked, so it is necessary to construct a dynamic electromagnetic fingerprint feature model according to the dynamic change characteristics of the equipment, and to identify the dynamic electromagnetic fingerprint combined with the features of the real-time monitoring data, to obtain more accurate and safe anomaly identification results.

[0033] Please refer to Figure 1 which shows the system block diagram of the industrial equipment runtime electromagnetic fingerprint real-time monitoring and anomaly identification system provided by the embodiment of the present application, which includes the following modules:

[0034] The data denoising module is used for acquiring the electromagnetic signal curve of the target equipment; acquiring the noise points in the electromagnetic signal curve according to each residual point in the residual term corresponding to the electromagnetic signal curve and the residual points adjacent to each residual point; and replacing the values of the noise points in the electromagnetic signal curve to acquire the denoised electromagnetic signal curve.

[0035] The electromagnetic signal of the target device is monitored in the near field using an electromagnetic sensor, specifically by installing a probe within a few centimeters of the device, collecting the electromagnetic signal of the device, and collecting the frequency at 10 Hz. The collection starts from the start of the device, and the real-time collected electromagnetic signal is stored in the database of the terminal in sequence format. The real-time newly collected signal data is inserted into the end of the sequence in order. The collected electromagnetic signal data is projected into a two-dimensional rectangular coordinate system to obtain an electromagnetic signal curve. The coordinate horizontal axis is the collection time sequence, and the coordinate vertical axis is the electromagnetic signal intensity of the target device. The adjacent points of the electromagnetic signal curve in the horizontal direction are connected.

[0036] During normal signal collection, there will be certain noise interference. The electromagnetic fingerprint is constructed by extracting the characteristics existing in the electromagnetic signal curve. Therefore, when there are noise points or abnormal data points in the electromagnetic signal curve, it will affect the accuracy of the construction of the electromagnetic fingerprint, and the constructed electromagnetic fingerprint may differ from the actual normal running state of the device. Therefore, the data points on the electromagnetic signal curve are first denoised.

[0037] First, the data points on the electromagnetic signal curve are decomposed in STL time sequence to obtain the decomposed residual term. The residual term is in a new two-dimensional coordinate system, the horizontal axis of the coordinate system is the same as the original coordinate system, and the vertical axis is the residual value. Each residual point in the residual term reflects the degree of inconsistency of the point in the original curve with periodicity and trend. Therefore, the more the residual point deviates, the more likely it is that the corresponding data point is an abnormal noise point. The mean of all residual points is obtained, which represents the general level of the residual. The difference between each residual point and the mean is obtained. The greater the difference between the residual point and the residual mean, the more the point deviates from the general level of the residual, and the greater the degree of noise abnormality of the point. However, if the residual has a clustering outlier, it indicates that the data in this part of the original curve has changed significantly, which has a positive significance for the construction of the electromagnetic fingerprint, rather than a single burst noise point. Therefore, it is necessary to further combine the distribution relationship of the residual point and other residual points in the neighborhood. When the straight-line distance between the residual point and the adjacent residual point is relatively far, the data point corresponding to the residual point is more likely to be an abnormal noise point.

[0038] Thus, the noise points in the electromagnetic signal curve are obtained according to the residual points in the residual term corresponding to the electromagnetic signal curve and the adjacent residual points of each residual point. Specifically, the absolute value of the difference between the residual value of a residual point in the residual term corresponding to the electromagnetic signal curve and the mean of the residual values of all residual points in the residual term is obtained, and the overall difference of the residual point is obtained by normalization. The sum of the absolute values of the differences between the residual value of the residual point and the residual values of the residual points adjacent to it before and after it is calculated and normalized to obtain the neighborhood distance of the residual point. The overall difference and the neighborhood distance of the residual point are added and averaged to obtain the noise abnormality degree of the residual point.

[0039] The calculation model of the noise anomaly degree of the residual point is specifically:

[0040] ,

[0041] wherein, represents the noise anomaly degree of the pth residual point, is the residual value of the pth residual point, is the average residual value of all residual points, represents the overall difference of the pth residual point, that is, the difference between the residual value of the pth residual point and the average residual value. The greater the difference, the more the residual point deviates from the general level of the residual, and the greater the noise anomaly degree of the point. is the residual value of the previous residual point of the pth residual point, represents the residual value of the next residual point of the pth residual point, that is, the residual values of the two adjacent residual points before and after the pth residual point, is the neighborhood distance of the pth residual point. The farther the distance, the more the residual point has the mutation characteristics of signal noise, and the stronger the noise anomaly degree. Otherwise, the closer the distance, the more likely the residual point is a signal fluctuation point with characteristic changes, and the weaker the noise anomaly degree. Norm represents the normalization operation.

[0042] Because noise is inevitably present in the signal monitoring and acquisition process, the noise anomaly degree of the residual point is calculated. and are linearly normalized and then averaged to obtain , the value range of which is 0 to 1, which can divide the data points with signal noise characteristics and normal data points at both ends of the value range. Thus, the first preset threshold is set to the boundary 0.5 in the value range. If the noise anomaly degree of a residual point is greater than or equal to the first preset threshold, it is considered that the residual point has noise anomaly characteristics, and the data point corresponding to the residual point is a noise point. Thus, the noise points are obtained by analyzing each residual point in the residual term corresponding to the electromagnetic signal curve.

[0043] Further, the value of the noise point is replaced by the average value of the values of the data points adjacent to the noise point in the electromagnetic signal curve pair, thereby filtering all noise data in the acquired electromagnetic signal curve to obtain a denoising electromagnetic signal.

[0044] The feature extraction module is configured to acquire the period of the denoising electromagnetic signal curve, and acquire a first feature, a second feature and a third feature of the period according to the average value of the data points in the period, the maximum peak value and the slope between every two adjacent data points of the denoising electromagnetic signal curve.

[0045] After filtering out the noise points without electromagnetic fingerprint characteristics, a feature extraction model is constructed to obtain the electromagnetic fingerprint of the electromagnetic signal dynamics of the monitoring device.

[0046] In order to obtain the dynamic change characteristics of the noise reduction electromagnetic signal curve, the noise reduction electromagnetic signal curve is cut with the period of the noise reduction electromagnetic signal curve as the window to form the dynamic change characteristics of the electromagnetic signal through the change characteristics between different periods. The STL time sequence decomposition is used on the data points of the noise reduction electromagnetic signal curve to obtain the seasonal term with the period characteristics, the Fourier transform is performed on the time domain data in the seasonal term to obtain the converted frequency domain data, and the frequency corresponding to the peak point data with the highest peak value (the largest peak point) in the frequency domain data is obtained. The frequency is the main frequency of the seasonal term data, and the period obtained by the reciprocal of the frequency is the main period of the seasonal term data. Because the seasonal term has the main periodic characteristics of the original curve, the main period of the seasonal term data is used to represent the period of the noise reduction electromagnetic signal curve, that is, the period of the noise reduction electromagnetic signal curve. After obtaining the period of the noise reduction electromagnetic signal curve, the noise reduction electromagnetic signal curve is cut according to the period length to obtain a plurality of periods.

[0047] Further, the data points in each period are analyzed to extract the characteristics of the data points in each period. The first feature, the second feature and the third feature of a period are obtained according to the mean value, the maximum peak value and the slope between each two adjacent data points of the data points in the period on the noise reduction electromagnetic signal curve.

[0048] Specifically, the mean value and the maximum peak value of the data points in a period are obtained as the value distribution characteristics in the period, which are respectively recorded as the first feature and the second feature of the period.

[0049] However, only relying on the value distribution characteristics (the first feature and the second feature) as the fingerprint characteristics of the period has poor accuracy. Therefore, the third feature is constructed based on the slope between each two adjacent data points in the period. The slope distribution chain code is constructed according to the slope between each two adjacent data points in a period. Specifically, eight slope intervals are obtained by uniformly dividing the 180-degree range, and each slope interval corresponds to a chain code value; the chain code value corresponding to the slope between each two adjacent data points is determined based on the slope interval to which the slope between the two adjacent data points belongs, and the chain code sequence corresponding to the period is obtained by sorting the chain code values according to the arrangement order of the data points in the period, which is recorded as the third feature of the period.

[0050] After 180 degrees are equally divided, the slope corresponding to the 22.5-degree inclined line is 0.14, the slope corresponding to the 50-degree inclined line is 1.19, and the slope corresponding to the 72.5-degree inclined line is 3.17, so the eight slope intervals are 、 、 、 、 、 、 , For the slopes within the eight slope intervals, eight chain code values ​​from 1 to 8 are set, such as... Figure 2 As shown, the chain code value can be used to describe the shape trend between every two adjacent data points within one cycle of the noise-reduced electromagnetic signal curve. The overall chain code can characterize the fluctuation characteristics of the data within the cycle. Thus, the first, second, and third characteristics of the data within each cycle can be obtained. By combining the static basis of the mean and peak values ​​(first and second characteristics) with the dynamic slope change characteristics between data points (third characteristic), the data characteristics representing the electromagnetic signal of the device within the cycle can be obtained more accurately.

[0051] The feature difference analysis module is used to obtain the first feature difference sequence, the second feature difference sequence, and the third feature difference sequence based on the differences between the first feature, the second feature, and the third feature in every two adjacent periods.

[0052] After obtaining the first, second, and third features corresponding to each cycle, the differences in features between adjacent cycles are further analyzed.

[0053] Specifically, the absolute value of the difference between the mean values ​​of data points in two adjacent periods is taken as the first characteristic difference between the two adjacent periods; the absolute value of the difference between the maximum peak values ​​of data points in two adjacent periods is taken as the second characteristic difference between the two adjacent periods; the mean of the absolute values ​​of the differences between the corresponding chain code values ​​in the chain code sequences of two adjacent periods is taken as the third characteristic difference between the two adjacent periods; the first characteristic difference, second characteristic difference, and third characteristic difference of every two adjacent periods in the noise-reduced electromagnetic signal curve are arranged in chronological order to obtain the first characteristic difference sequence, the second characteristic difference sequence, and the third characteristic difference sequence.

[0054] The specific calculation models for the first feature difference, the second feature difference, and the third feature difference are as follows:

[0055] ,

[0056] in, This represents the first characteristic difference between two adjacent periods, which is the absolute value of the difference between the means of data points in two adjacent periods. and These represent the mean of the data points in the previous period and the mean of the data points in the next period, respectively. This represents the second characteristic difference between two adjacent periods. and These represent the maximum peak value of the data points in the previous period and the maximum peak value of the data points in the next period, respectively; represents the third characteristic difference between two adjacent periods. represents the number of chain codes in a chain code sequence of a period, represents the chain code value of the i-th chain code in the chain code sequence of the previous period of the two adjacent periods, represents the chain code value of the i-th chain code in the chain code sequence of the later period of the two adjacent periods, represents the average difference of the chain code values of all corresponding chain codes in the chain code sequences of the two adjacent periods.

[0057] The characteristic differences between these periods represent the dynamic change characteristics between every two periods in the denoised electromagnetic signal curve. Each characteristic difference forms a sequence, and the first, second and third characteristic difference sequences are obtained. The three sequences are arranged in time sequence and can reflect the dynamic change characteristic rules between different periods of electromagnetic signal data.

[0058] The anomaly monitoring module is configured to obtain residual terms of the first, second and third characteristic difference sequences, respectively, and record them as the first residual term, the second residual term and the third residual term. The anomaly monitoring module is configured to determine whether the current electromagnetic fingerprint is abnormal according to the last residual point and the other residual points in the first residual term, the second residual term and the third residual term.

[0059] After obtaining the first, second and third characteristic difference sequences, the time length of a period of the denoised electromagnetic signal curve is taken as a monitoring time interval. That is, when the real-time collected electromagnetic signal meets the length of a period, the analysis is performed to obtain the monitoring result. The last period in the denoised electromagnetic signal curve is the current period, and the last element in the first, second and third characteristic difference sequences represents the current characteristic difference. Thus, the current situation can be analyzed.

[0060] Further, the first, second and third characteristic difference sequences are subjected to STL time sequence decomposition to obtain residual terms of the first, second and third characteristic difference sequences, respectively, and record them as the first residual term, the second residual term and the third residual term. When the data collected in the current period is analyzed, the more outlying the corresponding residual point is in the multiple characteristic residual term data, the less the data collected in the current period conforms to the periodicity and trend of the dynamic change rule of the entire curve, and the less the current period conforms to the dynamic change characteristic rule between periods. Therefore, the current period is more likely to be abnormal electromagnetic signal data with attack risk. The last residual point in the first residual term, the second residual term and the third residual term is obtained by analyzing the data in the current period, that is, the time corresponding to the last residual point is the current time.

[0061] Finally, whether the current electromagnetic fingerprint is abnormal is judged according to the last residual point and other residual points in the first residual term, the second residual term and the third residual term.

[0062] Specifically, the absolute value of the difference between the residual value of the last residual point in the first residual term and the average of the residual values of other residual points in the first residual term is obtained, and is normalized to obtain the first residual deviation degree; the absolute value of the difference between the residual value of the last residual point in the second residual term and the average of the residual values of other residual points in the second residual term is obtained, and is normalized to obtain the second residual deviation degree; the absolute value of the difference between the residual value of the last residual point in the third residual term and the average of the residual values of other residual points in the third residual term is obtained, and is normalized to obtain the third residual deviation degree; the average of the first residual deviation degree, the second residual deviation degree and the third residual deviation degree is obtained to obtain the current abnormality degree.

[0063] The calculation model of the current abnormality degree is specifically:

[0064] ,

[0065] Among them, W represents the current abnormality degree, which is also the abnormality degree corresponding to the current period. Since the fixed data points in the first, second and third feature difference sequences are obtained by the feature difference between periods, the current period is represented as a single point in the first, second and third feature difference sequences. represents the residual value of the last residual point in the first residual term, that is, the residual value obtained by analyzing the electromagnetic signal data of the current period, represents the average of the residual values of other residual points in the first residual term, represents the first residual deviation degree, which is the difference between the residual value of the last residual point in the first residual term (the residual value corresponding to the current time) and the average of the residual values of other residual points. The greater the difference, the more outlying the average feature residual value of the current period (the first feature), and the less the average feature conforms to the dynamic change characteristic rule within the period;

[0066] represents the residual value of the last residual point in the second residual term, represents the average of the residual values of other residual points in the second residual term, represents a second residual deviation degree, which is a difference between a residual value of a last residual point in the second residual term (a residual value corresponding to the current time) and a mean value of residual values of other residual points, and the greater the difference, the more outlying the maximum peak feature (second feature) residual value of the current period, and the less the maximum peak feature in the period conforms to the dynamic change characteristic rule;

[0067] represents a residual value of a last residual point in the third residual term, represents a mean value of residual values of residual points other than the last residual point in the third residual term, represents a third residual deviation degree, which is a difference between a residual value of a last residual point in the third residual term (a residual value corresponding to the current time) and a mean value of residual values of other residual points, and the greater the difference, the more outlying the chain code sequence (third feature) residual value of the current period, and the less the third feature in the period conforms to the dynamic change characteristic rule. norm is a normalization operation uniform formula magnitude.

[0068] Thus, the current abnormality degree can be obtained. Since the dynamic electromagnetic fingerprint of the abnormal feature with an attack risk does not have a dynamic change characteristic rule and is greatly different from the dynamic electromagnetic fingerprint in normal operation, the median 0.5 in the abnormality degree value range is set as a second preset threshold value. If the current abnormality degree is greater than the second preset threshold value, it is considered that the electromagnetic fingerprint of the monitored data has an abnormality and there is a suspected attack risk. Thus, a relatively accurate abnormality recognition result is obtained through the dynamic change characteristic of the electromagnetic fingerprint, and the attack by a copied static feature is not easy.

[0069] In summary, the application analyzes the dynamic change characteristic of the electromagnetic signal data, extracts the feature of each period, and determines whether there is an abnormality according to the similarity between the dynamic characteristic of the electromagnetic signal data in the current period and the dynamic electromagnetic fingerprint, thereby improving the accuracy of real-time monitoring and identification of abnormalities.

[0070] It should be noted that the above-mentioned order of the embodiments of the application is only for description, and does not represent the advantages and disadvantages of the embodiments. The above describes a specific embodiment of the present application. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are possible or can be advantageous.

[0071] Each embodiment in the present specification is described in a progressive manner, and the same or similar parts of each embodiment can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0072] The above merely describes preferred embodiments of the present application, and is not used to limit the present application, any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included in the protection scope of the present application.

Claims

1. An industrial equipment runtime electromagnetic fingerprint real-time monitoring and anomaly identification system, characterized in that, The system comprises: a data denoising module, configured to acquire an electromagnetic signal curve of a target device; acquire noise points in the electromagnetic signal curve according to each residual point in a residual term corresponding to the electromagnetic signal curve and residual points adjacent to each residual point; and replace values of the noise points in the electromagnetic signal curve to acquire a denoised electromagnetic signal curve; a feature extraction module, configured to acquire a period of the denoised electromagnetic signal curve; acquire a first feature, a second feature and a third feature of the period according to a mean value of data points in one period of the denoised electromagnetic signal curve, a maximum peak value and a slope between each two adjacent data points; and construct a dynamic electromagnetic fingerprint based on period division, wherein the electromagnetic fingerprint comprises the first feature, the second feature and the third feature; a feature difference analysis module, configured to acquire a first feature difference sequence, a second feature difference sequence and a third feature difference sequence according to differences between the first features of each two adjacent periods, differences between the second features and differences between the third features; an anomaly monitoring module, configured to acquire residual terms of the first, second and third feature difference sequences respectively, and record them as a first residual term, a second residual term and a third residual term; acquire a first residual deviation degree, a second residual deviation degree and a third residual deviation degree corresponding to the first residual term, the second residual term and the third residual term respectively according to a deviation degree of a last residual point and other residual points except the last residual point in the first residual term, the second residual term and the third residual term; and determine whether the current electromagnetic fingerprint is abnormal according to the first residual deviation degree, the second residual deviation degree and the third residual deviation degree.

2. The system, as claimed in claim 1, wherein, The acquisition of the electromagnetic signal curve of the target device comprises: projecting collected electromagnetic signal data into a two-dimensional rectangular coordinate system to acquire an electromagnetic signal curve, wherein a horizontal axis of the electromagnetic signal curve is a collection time sequence and a vertical axis of the electromagnetic signal curve is an electromagnetic signal intensity of the target device.

3. The system, as claimed in claim 1, wherein, The acquisition of the noise points in the electromagnetic signal curve according to each residual point in a residual term corresponding to the electromagnetic signal curve and residual points adjacent to each residual point comprises: acquiring a residual value of a residual point in a residual term corresponding to the electromagnetic signal curve and a mean value of residual values of all residual points in the residual term to obtain a whole difference of the residual point; acquiring a sum of absolute values of differences between the residual value of the residual point and residual values of adjacent residual points before and after the residual point and normalizing the sum to obtain a neighborhood distance of the residual point; adding the whole difference and the neighborhood distance of the residual point and averaging the sum to obtain a noise point anomaly degree of the residual point; and if the noise point anomaly degree of the residual point is greater than or equal to a first preset threshold, a data point on the electromagnetic signal curve corresponding to the residual point is a noise point.

4. The system, as claimed in claim 1, wherein, The acquisition of the period of the denoised electromagnetic signal curve comprises: using STL time sequence decomposition on data points of the denoised electromagnetic signal curve to obtain a seasonal term; performing Fourier transform on time domain data in the seasonal term to obtain frequency domain data; acquiring a frequency corresponding to a maximum peak value point in the frequency domain data and recording the frequency as a main frequency; and obtaining a period of the denoised electromagnetic signal curve by inverting the main frequency.

5. The system, as claimed in claim 1, wherein, The first feature, the second feature and the third feature of the period are respectively obtained according to the mean value of the data points in the period, the maximum peak value and the slope between each two adjacent data points, and the method comprises the following steps: The mean value of the data points in the period and the maximum peak value are respectively taken as the first feature and the second feature of the period; eight slope intervals are obtained by uniformly dividing the 180-degree range, and each slope interval corresponds to a chain code value; the chain code value corresponding to the slope between each two adjacent data points is determined based on the slope interval to which the slope between each two adjacent data points belongs, and the chain code sequence corresponding to the period is obtained by sorting the chain code values according to the arrangement order of the data points in the period, and the third feature of the period is recorded.

6. The system, as claimed in claim 1, wherein, The first feature difference sequence, the second feature difference sequence and the third feature difference sequence are respectively obtained according to the difference between the first features of each two adjacent periods, the difference between the second features and the difference between the third features, and the method comprises the following steps: The absolute value of the difference between the mean values of the data points of the adjacent two periods is taken as the first feature difference of the adjacent two periods; the absolute value of the difference between the maximum peak values of the data points of the adjacent two periods is taken as the second feature difference of the adjacent two periods; the mean value of the absolute values of the differences between the corresponding chain code values in the chain code sequences of the adjacent two periods is taken as the third feature difference of the adjacent two periods; the first feature difference, the second feature difference and the third feature difference of each two adjacent periods in the noise-reduced electromagnetic signal curve are arranged in time sequence to obtain the first feature difference sequence, the second feature difference sequence and the third feature difference sequence.

7. The system, as claimed in claim 1, wherein the system is configured to: The residual terms of the first feature difference sequence, the second feature difference sequence and the third feature difference sequence are respectively obtained, and the method comprises the following steps: The residual terms of the first feature difference sequence, the second feature difference sequence and the third feature difference sequence are obtained by performing STL time series decomposition on the first feature difference sequence, the second feature difference sequence and the third feature difference sequence.

8. The system, as claimed in claim 1, wherein, The first residual deviation degree, the second residual deviation degree and the third residual deviation degree corresponding to the first residual term, the second residual term and the third residual term are respectively obtained according to the last residual point in the first residual term, the second residual term and the third residual term and the deviation degree of the other residual points except the last residual point, and whether the current electromagnetic fingerprint is abnormal is judged according to the first residual deviation degree, the second residual deviation degree and the third residual deviation degree, and the method comprises the following steps: The absolute value of the difference between the residual value of the last residual point in the first residual term and the average of the residual values of the other residual points in the first residual term is obtained, and normalized to obtain a first residual deviation degree; the absolute value of the difference between the residual value of the last residual point in the second residual term and the average of the residual values of the other residual points in the second residual term is obtained, and normalized to obtain a second residual deviation degree; the absolute value of the difference between the residual value of the last residual point in the third residual term and the average of the residual values of the other residual points in the third residual term is obtained, and normalized to obtain a third residual deviation degree; the average of the first residual deviation degree, the second residual deviation degree and the third residual deviation degree is obtained to obtain a current abnormality degree; if the current abnormality degree is greater than a second preset threshold, the current electromagnetic fingerprint is abnormal.

Citation Information

Patent Citations

  • Brain wave processing method and system for evaluating mental stress

    CN117838150A

  • Characterizing a computer system using radiating electromagnetic signals monitored through an interface

    US20100023282A1