Industrial control safety cheating detection method and system based on container technology

By employing a container-based industrial control system security deception detection method, and utilizing multi-layer directed graph and parameter dependency graph analysis techniques, combined with state transition matrices and attack behavior knowledge bases, response data is dynamically generated. This addresses the shortcomings of existing industrial control system security protection technologies in identifying complex attacks, achieving accurate identification and proactive defense, and improving the security and reliability of industrial control systems.

CN121077834AActive Publication Date: 2025-12-05BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Patent Information

Application Number
CN202511632436.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-10
Publication Date
2025-12-05
Estimated Expiration
2045-11-10

AI Technical Summary

Technical Problem

Existing industrial control system security technologies have limited ability to detect complex attacks, struggle to identify advanced persistent threats, lack intelligent interaction capabilities, cannot dynamically adjust defense strategies, and have insufficient detection effectiveness and forensic value.

Method used

The industrial control system security deception detection method based on container technology obtains access requests from the industrial control system, guides them to a simulation service instance, constructs a multi-layer directed graph and parameter dependency graph, and dynamically generates response data to deceive attackers and implement isolation by combining a state transition matrix and an attack behavior knowledge base.

Benefits of technology

It enables accurate identification and classification of attack behaviors, improves the accuracy and reliability of security protection for industrial control systems, provides early warning and proactive defense capabilities, and ensures the safe operation of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077834A_ABST
    Figure CN121077834A_ABST
Patent Text Reader

Abstract

The invention provides an industrial control security spoofing detection method and system based on a container technology, and relates to the technical field of industrial control network security, and the method comprises the steps: guiding an abnormal access request to a simulation service instance in a container environment, extracting an interactive operation to construct a multilayer directed graph, calculating a branch entropy value and a semantic deviation degree to form a feature vector, and carrying out the spoofing detection of the abnormal access request; and determining an attack stage based on the state transition matrix and the attack behavior knowledge base, controlling response data and implementing network isolation. The method can actively induce the attacker to expose the intention, accurately recognize the attack stage, and effectively protect the industrial control system from network attack.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial control network security, and in particular to an industrial control security deception detection method and system based on container technology. BACKGROUND

[0002] Industrial control systems, as the nerve center of critical infrastructure, bear the important responsibility of production process monitoring and command execution. With the rapid development of industrial internet, industrial control systems have gradually realized network and informationization, but at the same time, they are also facing increasingly serious network security threats. The traditional industrial control system design mainly considers system reliability and real-time performance, and the security protection mechanism is relatively weak. Once attacked, it may lead to production interruption, equipment damage, and even serious consequences such as personnel injury.

[0003] In the field of industrial control security protection, signature-based intrusion detection systems and anomaly-based behavior analysis systems are currently the mainstream protection means. Signature detection identifies malicious behavior by comparing known attack characteristics, while anomaly detection detects operations that deviate from the normal mode by establishing a normal behavior baseline. In addition, boundary protection measures such as security isolation and access control are also widely used in industrial control environments. In recent years, honeypot technology, as an active defense means, simulates a real industrial control environment to attract attackers and provides valuable threat intelligence for security analysis.

[0004] The existing industrial control security protection technology still has some defects and deficiencies. The traditional industrial control security detection method has limited perception ability for attack behavior, especially for complex attacks such as advanced persistent threats. It is difficult to effectively identify through simple feature matching, resulting in low detection rate and high false positive rate. These complex attacks often use multi-stage penetration strategies, and single-point detection is difficult to grasp the whole picture of the attack. The existing industrial control deception defense system lacks intelligent interaction capability, and most of them can only provide static response or limited interaction logic. It is difficult to dynamically adjust the defense strategy according to the attacker's behavior, difficult to attract attackers for a long time and collect complete attack evidence, and reduces the effect and evidence value of deception defense. The semantic understanding of industrial protocol interaction is insufficient. The existing technology mainly focuses on network layer and transport layer features, and the semantic association and influence propagation analysis of command parameters in industrial protocols are not deep enough. It is difficult to accurately identify attack intentions from the protocol semantic level, especially for fine-grained attacks that use legal commands but have abnormal parameters. The detection effect is limited. SUMMARY

[0005] The embodiment of the present application provides an industrial control security deception detection method and system based on container technology, which can solve the problems in the prior art.

[0006] In a first aspect of the embodiment of the present application, an industrial control security deception detection method based on container technology is provided, comprising: An access request of an industrial control system is acquired, and when a preset abnormal behavior judgment condition is met, the access request is guided to a simulation service instance in a container environment; A plurality of interaction operations of the simulation service instance are extracted, the interaction operations are mapped to nodes in a multi-layer directed graph and directed edges carrying transition weights are established, weighted connection degrees of each node are calculated based on the transition weights, and a branch entropy value is calculated; Control instructions in the interaction operations are parsed and parameter fields are extracted, the parameter fields are compared with predefined data types and value ranges, a parameter dependency graph is constructed and an influence propagation path is tracked, a semantic deviation degree is calculated, and the branch entropy value and the semantic deviation degree are combined into a feature vector; The feature vector is input into a state transition matrix to calculate a transition probability value, stage cycle characteristics and standard transition probability distributions of each attack stage are extracted from a preset attack behavior knowledge base based on cycle matching degrees and probability distribution divergences, and a current attack stage is determined based on weighted fusion; Based on the current attack stage, a delay time parameter and a response template are determined to generate response data, and the simulation service instance is controlled to return the response data; Based on the current attack stage, network access requests are isolated.

[0007] In an optional embodiment, extracting a plurality of interaction operations of the simulation service instance, mapping the interaction operations to nodes in a multi-layer directed graph and establishing directed edges carrying transition weights, calculating weighted connection degrees of each node based on the transition weights, and calculating a branch entropy value include: Network data packets of each interaction operation received by the simulation service instance are parsed, timestamps, operation type identifiers and protocol level identifiers of each interaction operation are extracted, each interaction operation is sorted according to the timestamp, each interaction operation is divided into application layer operations and transport layer operations based on the protocol level identifier, and each sorted interaction operation is mapped to a node in a multi-layer directed graph; Each node in the multi-layer directed graph is traversed, when the timestamp of a previous node is earlier than that of a subsequent node, the operation type identifier combination of the previous node and the subsequent node is extracted, it is determined whether the operation type identifier combination constitutes a valid transition path by querying a preset operation transition constraint table, and when the valid transition path is constituted, a directed edge carrying a transition weight is established between the previous node and the subsequent node; Each node in the multi-layer directed graph is taken as a target node, the number of directed edges pointing to the target node is counted to determine the number of predecessor nodes, the number of directed edges pointed by the target node is counted to determine the number of successor nodes, the number of predecessor nodes and the number of successor nodes are weighted and accumulated based on the corresponding transition weights, and the weighted connection degree of each node is obtained; Based on the ratio of the weighted connection degree of each node to the sum of the weighted connection degrees of all nodes, the probability distribution of each node is determined, and the branch entropy value of the operation sequence is calculated based on the information entropy of the probability distribution.

[0008] In an alternative embodiment, the control instructions in the interactive operation are parsed and the parameter fields are extracted, the parameter fields are compared with predefined data types and value ranges, a parameter dependency graph is constructed and an influence propagation path is tracked, a semantic deviation degree is calculated, and a branch entropy value is combined with the semantic deviation degree into a feature vector, including: The control instructions in each interactive operation are parsed, the instruction operation code and the parameter field are extracted, the corresponding parameter definition rule is queried from the industrial protocol specification library, the predefined data type, the predefined value range, and the constraint relationship between the parameters are obtained; The actual data type of the parameter field is matched with the predefined data type, and when the actual data type is inconsistent with the predefined data type, it is marked as a data type deviation. The actual value of the parameter field is interval judged with the predefined value range, and when the actual value exceeds the predefined value range, it is marked as a value range deviation. The total number of data type deviation and value range deviation is counted to determine the number of parameter deviation; Based on the constraint relationship between the parameters, a parameter dependency graph is constructed, and propagation simulation is performed from the deviation source node along the parameter dependency graph to determine the influence propagation path. The influence diffusion degree is calculated based on the influence propagation path; The basic deviation rate is calculated based on the number of parameter deviations and the total number of parameter fields. The diffusion deviation rate is calculated based on the influence diffusion degree of each parameter deviation field and the total number of parameter nodes in the parameter dependency graph. The semantic deviation degree is obtained by fusing the basic deviation rate and the diffusion deviation rate; The branch entropy value of the operation sequence and the semantic deviation degree are normalized and combined to construct a feature vector.

[0009] In an alternative embodiment, based on the constraint relationship between the parameters, a parameter dependency graph is constructed, and propagation simulation is performed from the deviation source node along the parameter dependency graph to determine the influence propagation path. The influence diffusion degree is calculated based on the influence propagation path, including: The constraint relationship between the parameters is parsed, the numerical association constraint and the time sequence constraint between the parameter fields are extracted, and each parameter field is taken as a parameter node. When there is a numerical association constraint between the first parameter field and the second parameter field, an association edge is established in the direction from the first parameter field to the second parameter field and the constraint condition is marked. When there is a time sequence constraint between the first parameter field and the second parameter field, a time sequence edge is established and the time sequence interval is marked. A parameter dependency graph containing association edges and time sequence edges is constructed; Locating parameter fields with data type deviation or value range deviation in the parameter dependency graph determines deviation source nodes, propagates from each deviation source node along associated edges and time edges, extracts constraint conditions marked on each edge in the propagation process, determines whether downstream parameter nodes trigger constraint violation when deviation occurs at the current deviation source node, marks downstream parameter nodes as affected nodes when downstream parameter nodes trigger constraint violation and continues to propagate downstream, and terminates the propagation branch when downstream parameter nodes do not trigger constraint violation, records propagation links formed from the deviation source node to each affected node, and determines the influence propagation path. Count the number of affected nodes corresponding to each deviation source node, extract the number of edges passed in each influence propagation path as the propagation depth, and calculate the influence diffusion degree of each deviation source node based on the number of affected nodes and the propagation depth.

[0010] In an optional embodiment, the feature vector is input into a state transition matrix to calculate transition probability values, the stage cycle feature and the standard transition probability distribution of each attack stage are extracted from a preset attack behavior knowledge base, and the current attack stage is determined based on the cycle matching degree and the probability distribution divergence weighted fusion, including: The pre-defined attack stage sequence and the state transition matrix corresponding to each attack stage are extracted from the preset attack behavior knowledge base, the feature vector is input into the state transition matrix, the transition probability values from the current state to each candidate state are calculated, and the current observation transition probability distribution is constructed; The historical interaction sequence samples of each attack stage are extracted from the attack behavior knowledge base, the state transition directed graph of each attack stage is constructed, the cycle path is identified in the state transition directed graph, the cycle length and cycle frequency of the cycle path are calculated, the cycle path is divided into multiple cycle mode groups, and the stage cycle feature is determined by extracting the cycle mode core feature; The state transition sequence corresponding to the current observation transition probability distribution is analyzed, the state transition sequence is matched with the stage cycle feature of each attack stage, the ratio of the number of matched state nodes to the total number of state transition sequences is calculated, and the cycle matching degree is determined; The probability distribution divergence between the current observation transition probability distribution and the standard transition probability distribution of each attack stage is calculated, the probability distribution divergence and the cycle matching degree of the corresponding attack stage are weighted and fused to obtain the stage matching degree, and the attack stage with the highest stage matching degree is selected as the current attack stage.

[0011] In an optional embodiment, the cycle path is identified in the state transition directed graph, the cycle length and cycle frequency of the cycle path are calculated, the cycle path is divided into multiple cycle mode groups, and the stage cycle feature is determined by extracting the cycle mode core feature, including: In the state transition directed graph, a circular path starting from a starting state node and returning to the starting state node through multiple intermediate state nodes is identified by a depth-first search algorithm, a sequence of state nodes and a sequence of state transition edges in the circular path are extracted, a number of state nodes in the circular path is calculated to determine a circular length, and a frequency of occurrence of the circular path in the historical interaction sequence sample is calculated to determine a circular frequency; A circular length difference and a circular frequency difference between the circular paths are calculated, when the circular length difference is less than a preset length threshold value and the circular frequency difference is less than a preset frequency threshold value, the circular paths are divided into the same circular pattern group, a public state node subsequence and a public state transition edge subsequence of the circular paths in each circular pattern group are extracted, a circular pattern core feature is determined, and the circular pattern core feature, a corresponding circular length range and a circular frequency range are combined to determine a stage circular feature.

[0012] In an alternative embodiment, based on the current attack stage, a delay time parameter and a response template are determined to generate response data, and the simulation service instance is controlled to return the response data, comprising: According to the current attack stage, a delay time parameter and a response template corresponding to the attack stage are extracted from a preset strategy library; The adjustment field in the response template is parsed, the data type and the value constraint range of the adjustment field are obtained, the induction direction of the adjustment field is determined based on the attack feature of the current attack stage, and the boundary value in the value constraint range is selected as the induced numerical value along the induction direction; The initial value of the adjustment field is replaced by the induced numerical value, the initial values of the non-adjustment fields in the response template are kept unchanged, the response data containing the induced numerical value is generated, and the response sending time is calculated based on the current time and the delay time parameter; The simulation service instance is controlled to return the response data to the attack source at the response sending time.

[0013] In a second aspect of the embodiment of the application, a container technology-based industrial control security deception detection system is provided, comprising: A first unit is configured to obtain an access request of an industrial control system, and when a preset abnormal behavior determination condition is met, the access request is guided to a simulation service instance in a container environment; A second unit is configured to extract multiple interaction operations of the simulation service instance, map the interaction operations into nodes in a multi-layer directed graph and establish directed edges carrying transition weights, calculate weighted connection degrees of each node based on the transition weights, and calculate branch entropy values; A third unit is configured to parse control instructions in the interaction operations and extract parameter fields, compare the parameter fields with predefined data types and value ranges, construct a parameter dependency graph and track an influence propagation path, calculate a semantic deviation degree, and combine the branch entropy values and the semantic deviation degree into a feature vector; The fourth unit is configured to input the feature vector into a state transition matrix to calculate a transition probability value, extract stage cycle features and standard transition probability distribution of each attack stage from a preset attack behavior knowledge base, and determine the current attack stage based on weighted fusion of cycle matching degree and probability distribution divergence. The fifth unit is configured to determine a delay time parameter and a response template to generate response data based on the current attack stage, and control the simulation service instance to return the response data. The sixth unit is configured to isolate the network access request based on the current attack stage.

[0014] In a third aspect, the embodiment of the present application provides an electronic device, comprising: a processor; a memory configured to store processor-executable instructions; The processor is configured to invoke the instructions stored in the memory to execute the method described above.

[0015] In a fourth aspect, the embodiment of the present application provides a computer readable storage medium, which stores computer program instructions, and the computer program instructions are executed by a processor to implement the method described above.

[0016] In the embodiment of the present application, by guiding the suspicious access request to the simulation service instance in the container environment, combining the multi-layer directed graph and the parameter dependence graph analysis technology, the accurate identification and classification of attack behavior are realized, and the accuracy and reliability of the industrial control system security protection are effectively improved. The feature vector analysis method based on the branch entropy value and the semantic deviation degree synthesis, combined with the state transition matrix and the attack behavior knowledge base, can accurately identify the current attack stage, realize the early warning of attack intention, and enhance the active defense capability of the industrial control system. The dynamic adjustment of the delay time parameter and the response template generation mechanism can not only effectively deceive the attacker and delay the attack process, but also can implement accurate isolation when the attack occurs, maximize the security of the industrial control system, and provide sufficient response time for security personnel. BRIEF DESCRIPTION OF DRAWINGS

[0017] Figure 1 Fig. 1 is a flowchart of the industrial control security deception detection method based on the container technology according to the embodiment of the present application; Figure 2 Fig. 2 is a flowchart of the attack stage determination based on the fusion of state transition probability and cycle feature. DETAILED DESCRIPTION

[0018] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work belong to the protection scope of the present application.

[0019] The technical solutions of the present application will be described in detail in the following specific embodiments. The following several specific embodiments can be combined with each other, and some embodiments may not be described again for the same or similar concepts or processes.

[0020] Figure 1 The flowchart of the container technology-based industrial control security deception detection method of the embodiments of the present application is shown in FIG. 1. Figure 1 The method comprises the following steps. An access request of an industrial control system is acquired, and when a preset abnormal behavior judgment condition is met, the access request is guided to a simulation service instance in a container environment; Multiple interaction operations of the simulation service instance are extracted, the interaction operations are mapped to nodes in a multi-layer directed graph and directed edges carrying transition weights are established, weighted connection degrees of each node are calculated based on the transition weights, and branch entropy values are calculated; Control instructions in the interaction operations are parsed and parameter fields are extracted, the parameter fields are compared with predefined data types and value ranges, a parameter dependency graph is constructed and an influence propagation path is tracked, a semantic deviation degree is calculated, and the branch entropy values and the semantic deviation degree are integrated into a feature vector; The feature vector is input into a state transition matrix to calculate a transition probability value, stage cycle characteristics of each attack stage and a standard transition probability distribution are extracted from a preset attack behavior knowledge base, a current attack stage is determined based on weighted fusion of cycle matching degrees and probability distribution divergences; Based on the current attack stage, a delay time parameter and a response template are determined to generate response data, and the simulation service instance is controlled to return the response data; Based on the current attack stage, network access requests are isolated.

[0021] In an optional implementation, the multiple interaction operations of the simulation service instance are extracted, the interaction operations are mapped to nodes in a multi-layer directed graph and directed edges carrying transition weights are established, weighted connection degrees of each node are calculated based on the transition weights, and branch entropy values are calculated, which comprises the following steps. The network data packets of each interaction operation received by the analysis simulation service instance are parsed, the timestamp, operation type identifier and protocol level identifier of each interaction operation are extracted, each interaction operation is sorted according to the timestamp, each interaction operation is divided into application layer operation and transmission layer operation based on the protocol level identifier, and each sorted interaction operation is mapped into a node in the multi-layer directed graph; When the timestamp of the current sequence node is earlier than that of the subsequent node, the operation type identifier combination of the presequence node and the subsequent node is extracted, and it is determined whether the operation type identifier combination constitutes a valid transfer path by querying the preset operation transfer constraint table, and when a valid transfer path is constituted, a directed edge carrying a transfer weight is established between the presequence node and the subsequent node; With each node in the multi-layer directed graph as a target node, the number of directed edges pointing to the target node is counted to determine the number of predecessor nodes, the number of directed edges pointed by the target node is counted to determine the number of successor nodes, and the number of predecessor nodes and the number of successor nodes are weighted and accumulated based on the corresponding transfer weight to obtain the weighted connection degree of each node; Based on the ratio of the weighted connection degree of each node to the sum of the weighted connection degrees of all nodes, the probability distribution of each node is determined, and the branch entropy value of the operation sequence is determined based on the probability distribution and the information entropy.

[0022] In a specific embodiment, parsing the network data packets received by the analysis simulation service instance is the basis for building the interaction operation model. Each network data packet is deeply parsed to extract the timestamp information contained therein. The timestamp, usually in milliseconds, records the arrival time of the data packet. At the same time, the operation type identifier is extracted from the data packet. For example, for industrial control protocol data packets, the operation type identifier may be "read", "write", "control", etc. In addition, the protocol level identifier needs to be extracted to distinguish between application layer operations and transmission layer operations. For example, transmission layer operations include TCP connection establishment, data transmission, etc., and application layer operations include specific business requests and responses. After extraction, the interaction operations are time-sequenced sorted according to the timestamp to ensure that the directed graph constructed later can accurately reflect the order of operations. For the sorted operation set, it is divided into an application layer operation set and a transmission layer operation set according to the protocol level identifier. In the multi-layer directed graph, each operation is mapped to a node, and the node attributes include timestamp, operation type identifier and protocol level identifier.

[0023] For constructing the inter-node connection relationship of the multi-layer directed graph, all pairs of nodes in the graph need to be traversed. When the time precedence relationship of a pair of nodes is determined, i.e., the time stamp of the preceding node is earlier than that of the subsequent node, the operation type identifiers of the two nodes are extracted to form a two-tuple. Subsequently, a predefined operation transition constraint table is queried to determine whether the two-tuple constitutes a valid transition path. The operation transition constraint table is a two-dimensional matrix, with different operation types representing the rows and columns, respectively, and the matrix element values representing the validity and weight of the transition from the row operation type to the column operation type. For example, a transition path from a "read" operation to a "write" operation can be valid, while a transition path from a "control" operation to an "authentication" operation can not be allowed. When it is determined that the operation type identifier combination constitutes a valid transition path, a directed edge is established between the corresponding preceding node and the subsequent node, and the directed edge is assigned a corresponding transition weight. The transition weight can be set based on the importance, frequency, or security sensitivity of the operation, with a higher weight value indicating that the transition path is more important.

[0024] After the multi-layer directed graph is constructed, the weighted connection degrees of the nodes in the graph need to be calculated. For each node, the number of directed edges pointing to the node, i.e., the number of predecessor nodes, is counted; the number of directed edges pointing from the node, i.e., the number of successor nodes, is counted. Considering that different transition paths have different importance, the number of predecessor nodes and the number of successor nodes need to be weighted. Specifically, for each incoming edge of a node, the weight of the incoming edge is multiplied by the number of predecessor nodes; for each outgoing edge of a node, the weight of the outgoing edge is multiplied by the number of successor nodes. The contribution values of all weighted incoming edges and outgoing edges are accumulated to obtain the weighted connection degree of the node. The weighted connection degree reflects the importance and activity of the node in the interactive operation network.

[0025] Based on the weighted connection degrees of the nodes, the probability distribution of each node is calculated. For each node in the graph, its probability value is equal to the weighted connection degree of the node divided by the sum of the weighted connection degrees of all nodes. The probability distribution obtained in this way satisfies the constraint condition that the sum of all probability values is equal to 1. The probability distribution reflects the relative importance of each operation node in the interactive operation. Based on the obtained probability distribution, the information entropy is calculated as the branch entropy value of the operation sequence. Specifically, for the probability value of each node, the natural logarithm is calculated and multiplied by the probability value, and the products of all nodes are accumulated and taken as the negative value, i.e., the branch entropy value is obtained. The higher the branch entropy value, the greater the uncertainty of the interactive operation and the higher the complexity of the operation sequence.

[0026] Exemplarily, in a set of interoperations in an industrial control environment, assuming that 10 network packets are captured, the extracted information includes: packet 1 (timestamp: 1634567890123, operation type: connection request, protocol level: transport layer), packet 2 (timestamp: 1634567890456, operation type: connection confirmation, protocol level: transport layer), packet 3 (timestamp: 1634567891234, operation type: authentication request, protocol level: application layer), packet 4 (timestamp: 1634567892345, operation type: authentication response, protocol level: application layer), packet 5 (timestamp: 1634567893456, operation type: read request, protocol level: application layer), packet 6 (timestamp: 1634567894567, operation type: read response, protocol level: application layer), packet 7 (timestamp: 1634567895678, operation type: write request, protocol level: application layer), packet 8 (timestamp: 1634567896789, operation type: write response, protocol level: application layer), packet 9 (timestamp: 1634567897890, operation type: disconnect request, protocol level: transport layer), and packet 10 (timestamp: 1634567898901, operation type: disconnect confirmation, protocol level: transport layer).

[0027] After sorting by timestamp and dividing the protocol level, a multi-layer directed graph is constructed, in which the application layer includes packets 3, 4, 5, 6, 7, and 8, and the transport layer includes packets 1, 2, 9, and 10. By querying the operation transition constraint table, an effective transition path is established. For example, the weight from “connection request” to “connection confirmation” is 0.8, the weight from “connection confirmation” to “authentication request” is 0.9, the weight from “authentication request” to “authentication response” is 0.7, and so on.

[0028] For the node “authentication request”, its predecessor node is “connection confirmation”, its successor node is “authentication response”, the incoming edge weight is 0.9, the outgoing edge weight is 0.7, the number of predecessor nodes is 1, and the number of successor nodes is 1, so its weighted connectivity degree is 0.9×1+0.7×1=1.6. Similarly, the weighted connectivity degrees of other nodes are calculated, assuming that the sum of the weighted connectivity degrees of all nodes is 15.2, then the probability of the “authentication request” node is 1.6÷15.2≈0.105.

[0029] After calculating the probabilities of all nodes, the probability distribution is obtained as: connection request (0.053), connection confirmation (0.079), authentication request (0.105), authentication response (0.092), read request (0.118), read response (0.105), write request (0.132), write response (0.118), disconnect request (0.105), and disconnect confirmation (0.092). Based on the probability distribution, the branch entropy value is calculated as 2.28, indicating that the interactive operation sequence has certain complexity and uncertainty. Through the calculation of the branch entropy value, the behavior characteristics of the interactive operation can be quantitatively evaluated, providing data support for subsequent anomaly detection and behavior analysis.

[0030] In an alternative embodiment, the control instructions in the interactive operation are parsed and the parameter fields are extracted, the parameter fields are compared with the predefined data types and value ranges, the parameter dependency graph is constructed and the influence propagation path is tracked, the semantic deviation degree is calculated, and the branch entropy value and the semantic deviation degree are integrated into a feature vector, including: The control instructions in each interactive operation are parsed, the instruction operation code and the parameter field are extracted, the corresponding parameter definition rule is queried from the industrial protocol specification library, the predefined data type, the predefined value range, and the constraint relationship between the parameters are obtained; The actual data type of the parameter field is matched and determined with the predefined data type, and when the actual data type is inconsistent with the predefined data type, it is marked as data type deviation. The actual value of the parameter field is interval determined with the predefined value range, and when the actual value exceeds the predefined value range, it is marked as value range deviation. The total number of data type deviation and value range deviation is counted to determine the parameter deviation number; Based on the constraint relationship between the parameters, the parameter dependency graph is constructed, the influence propagation path is determined by propagating simulation along the parameter dependency graph from the deviation source node, and the influence diffusion degree is calculated based on the influence propagation path; The basic deviation rate is calculated based on the parameter deviation number and the total number of parameter fields, the diffusion deviation rate is calculated based on the influence diffusion degree of each parameter deviation field and the total number of parameter nodes in the parameter dependency graph, and the semantic deviation degree is obtained by fusing the basic deviation rate and the diffusion deviation rate; The branch entropy value and the semantic deviation degree of the operation sequence are normalized and combined to construct a feature vector.

[0031] In one embodiment, the control instruction generally includes an operation code and a parameter field. The interactive operation data stream is captured from the industrial control network, and the key information of each control instruction is extracted. For a write single register instruction in the Modbus protocol, the operation code is 0x06, and the parameter field includes the register address and the write value. For example, the captured instruction is "06 00 01 01F4", the operation code is 06, the register address is 0001, and the write value is 01F4 (decimal 500). The pre-established industrial control protocol specification library is queried, and the data type and value range of each type of register in the Modbus protocol are defined in the library. For the register with address 0001, the pre-defined data type is a 16-bit unsigned integer, and the value range is 0-400.

[0032] In the parameter verification stage, the compliance of the actual data with the pre-defined rules is checked. The data type of the write value 500 conforms to the definition of the 16-bit unsigned integer, so the data type match is correct; but the value 500 is out of the pre-defined value range 0-400, and the parameter is marked as value range deviation. For another instruction "06 00 02 FF FF" in the same operation sequence, the write value FFFF (decimal 65535) to the register address 0002 is parsed. According to the protocol specification library, the register is pre-defined as a 16-bit signed integer, and the value range is -100 to 100. FFFF is interpreted as 65535 as an unsigned integer and -1 as a signed integer, and there is ambiguity in the interpretation of the data type, which is marked as data type deviation; at the same time, -1 is within the value range under the signed interpretation, but due to the type deviation, it is still recorded in the parameter deviation statistics.

[0033] A parameter dependency graph is constructed based on the parameter constraint relationship in the protocol specification library. For example, in a certain PLC control program, register 0001 stores the temperature set value, register 0002 stores the control mode (0 for manual and 1 for automatic), and register 0003 stores the valve opening degree, and the valve opening degree depends on the temperature set value in the automatic mode. Accordingly, the dependency relationship is constructed: register 0002→register 0003, register 0001→register 0003 (conditional dependence on the value of register 0002 being 1). When the value of register 0001 is detected to deviate, the propagation simulation is performed along the dependency graph from the node. Since the current value of register 0002 is in manual mode, the temperature set value deviation will not propagate to the valve opening degree, and the influence path is limited to the node itself, and the influence diffusion degree is 1 / 3 (number of affected nodes / total number of nodes). When another operation modifies register 0002 to automatic mode, the deviation of register 0001 will propagate to register 0003 through the dependency path, and the influence diffusion degree increases to 2 / 3.

[0034] The semantic deviation degree calculation is divided into two parts: a basic deviation rate and a diffusion deviation rate. The basic deviation rate is a ratio of a parameter deviation number to a total number of parameter fields. In an operation sequence containing 10 instructions, a total of 20 parameter fields, if 2 parameters are detected to deviate, the basic deviation rate is 2 / 20=0.1. The diffusion deviation rate considers the influence diffusion degrees of each deviated parameter. If the influence diffusion degrees of two deviated parameters are 1 / 3 and 2 / 3 respectively, the comprehensive diffusion deviation rate is (1 / 3+2 / 3) / 3=1 / 3 (the total number of parameter dependency graph nodes is 3). Finally, the semantic deviation degree is calculated as 0.2 by weighted average fusion of the basic deviation rate and the diffusion deviation rate (assuming the weights are 0.6 and 0.4 respectively, then 0.6*0.1+0.4*0.33≈0.2).

[0035] The branch entropy value represents the uncertainty of the operation sequence, which is calculated by counting the frequency of each type of instruction in the operation sequence. For example, in an operation sequence containing 20 instructions, if the read instruction appears 8 times and the write instruction appears 12 times, the normalized branch entropy value is about 0.97. The normalized semantic deviation degree 0.2 and the branch entropy value 0.97 are combined into a two-dimensional feature vector [0.2, 0.97], which can be used for subsequent anomaly detection or behavior analysis.

[0036] Through the above method, the semantic deviation of the industrial control instruction parameter can be effectively recognized, and the branch characteristics of the operation sequence are combined to construct a feature vector that can reflect the abnormality of the operation behavior, providing data support for the security protection of the industrial control system.

[0037] In an optional implementation, a parameter dependency graph is constructed based on the constraint relationship between parameters, propagation simulation is performed along the parameter dependency graph from the deviation source node to determine the influence propagation path, and the influence diffusion degree is calculated based on the influence propagation path, including: The constraint relationship between parameters is analyzed, the numerical association constraint and the time sequence constraint between parameter fields are extracted, each parameter field is taken as a parameter node, when there is a numerical association constraint between a first parameter field and a second parameter field, an association edge is established in the direction from the first parameter field to the second parameter field and the constraint condition is marked, when there is a time sequence constraint between the first parameter field and the second parameter field, a time sequence edge is established and the time sequence interval is marked, and a parameter dependency graph containing the association edge and the time sequence edge is constructed; Locating parameter fields with data type deviation or value range deviation in the parameter dependency graph determines deviation source nodes, propagates from each deviation source node along the associated edges and the time sequence edges, extracts the constraint conditions marked on each edge in the propagation process, and determines whether the downstream parameter nodes trigger constraint violation when the current deviation source node deviates. When the downstream parameter nodes trigger constraint violation, mark the downstream parameter nodes as affected nodes and continue to propagate downstream. When the downstream parameter nodes do not trigger constraint violation, terminate the propagation branch, record the propagation links formed from the deviation source nodes to the affected nodes, and determine the influence propagation path. Count the number of affected nodes corresponding to each deviation source node, extract the number of edges passed in each influence propagation path as the propagation depth, and calculate the influence diffusion degree of each deviation source node based on the number of affected nodes and the propagation depth.

[0038] In a specific embodiment, during the parameter dependency graph construction phase, the constraint relationships between parameter fields are extracted from the database. Taking an industrial control system as an example, it includes temperature sensor parameter "temp", pressure parameter "pressure", flow parameter "flow", and valve opening parameter "valve". By analyzing system documents and historical data, the following constraint relationships can be extracted: when "temp" exceeds 80℃, "pressure" must be less than 2.5MPa; "flow" must reach the corresponding value within 5 seconds after "valve" adjustment, and the "flow" value should be the valve opening percentage multiplied by the maximum flow 10m 3 / h. These constraint relationships are divided into two categories: numerical association constraints and time sequence constraints.

[0039] For numerical association constraints, an associated edge is established from the constraint condition parameter to the constrained parameter. For example, an associated edge is established from "temp" to "pressure", and the constraint condition "temp>80℃ → pressure<2.5MPa" is marked. For the relationship between "valve" and "flow", an associated edge is established from "valve" to "flow", and the constraint condition "flow =valve% × 10m 3 / h" is marked.

[0040] For time sequence constraints, a time sequence edge representing the time sequence relationship between parameters is established. For example, a time sequence edge is established from "valve" to "flow", and the time interval "5 seconds" is marked, indicating that the flow should reach the corresponding value within 5 seconds after valve adjustment. In this way, a complete parameter dependency graph containing parameter nodes, associated edges and time sequence edges is constructed.

[0041] When a parameter deviation is detected, the impact propagation simulation is initiated. Assume that the "temp" parameter value is monitored to reach 95°C, which is beyond the normal operating range of 80°C, the "temp" node is marked as the source node of deviation. From this node, the propagation simulation is performed along the parameter dependency graph. The associated edges connected to "temp" are examined, and an associated edge pointing to "pressure" is found, with the constraint condition "temp > 80°C → pressure < 2.5MPa" annotated on the edge. Since the current "temp" value of 95°C satisfies the condition "temp > 80°C", it is determined that the "pressure" parameter is affected by the constraint and should be kept below 2.5MPa. If the current "pressure" actual value is 2.8MPa, which violates the constraint condition, the "pressure" node is marked as an affected node, and the propagation link from "temp" to "pressure" is recorded.

[0042] The propagation continues downstream from the "pressure" node, and the edges connected to "pressure" are examined. If an associated edge pointing to "flow" is found, with the constraint condition "pressure > 2.5MPa → flow < 2.5MPa" annotated on the edge, it is determined that the "flow" parameter is also affected by the constraint. If the current "flow" value is 9m / s, which violates the constraint condition, the "flow" node is also marked as an affected node, and the propagation link from "temp" via "pressure" to "flow" is recorded. 3 / h, which violates the constraint condition, the "flow" node is also marked as an affected node, and the propagation link from "temp" via "pressure" to "flow" is recorded.

[0043] For the propagation of temporal constraints, the time dimension is considered. For example, after the "valve" parameter changes, the temporal edges connected to it are examined, and a temporal edge pointing to "flow" is found, with the temporal interval "5 seconds" annotated on the edge. The "flow" parameter is monitored for changes within the subsequent 5 seconds, and if "flow" does not reach the expected value of "valve x 10m / s" after 5 seconds, the "flow" node is marked as a node affected by the temporal constraint. 3 / h, which violates the constraint condition, the "flow" node is also marked as an affected node, and the propagation link from "temp" via "pressure" to "flow" is recorded.

[0044] Through the above propagation simulation, the complete impact propagation path is obtained. For the "temp" deviation in this example, the impact propagation path is "temp → pressure → flow", the number of affected nodes is 2 (including "pressure" and "flow"), and the propagation depth is 2 (through two edges).

[0045] Based on the propagation path, the influence diffusion degree is calculated, and the influence diffusion degree is calculated according to the weighted combination of the number of affected nodes and the propagation depth. For example, the influence diffusion degree is set to "number of affected nodes x (1 + propagation depth / 10)". For the above "temp" deviation case, the influence diffusion degree is 2 x (1 + 2 / 10) = 2.4. If another parameter "valve" deviates only one node of "flow", the propagation depth is 1, and the influence diffusion degree is 1 x (1 + 1 / 10) = 1.1. By comparing the influence diffusion degrees of different parameters, it is identified that the key parameter "temp" has a greater influence, and the abnormal processing is preferentially performed.

[0046] In an optional embodiment, the feature vector is input into a state transition matrix to calculate a transition probability value, a stage cycle feature and a standard transition probability distribution of each attack stage are extracted from a preset attack behavior knowledge base, and a current attack stage is determined based on weighted fusion of cycle matching degree and probability distribution divergence, including: A predefined attack stage sequence and a state transition matrix corresponding to each attack stage are extracted from a preset attack behavior knowledge base, the feature vector is input into the state transition matrix, a transition probability value from a current state to each candidate state is calculated, and a current observation transition probability distribution is constructed; A historical interaction sequence sample of each attack stage is extracted from the attack behavior knowledge base, a state transition directed graph of each attack stage is constructed, a cycle path is identified in the state transition directed graph, a cycle length and a cycle frequency of the cycle path are calculated, the cycle path is divided into a plurality of cycle mode groups, and a cycle mode core feature is extracted to determine a stage cycle feature; The state transition sequence corresponding to the current observation transition probability distribution is analyzed, the state transition sequence is matched with the stage cycle feature of each attack stage, the ratio of the number of matched state nodes to the total number of state transition sequences is calculated, and the cycle matching degree is determined; The probability distribution divergence between the current observation transition probability distribution and the standard transition probability distribution of each attack stage is calculated, the probability distribution divergence and the cycle matching degree of the corresponding attack stage are weighted and fused to obtain a stage matching degree, and the attack stage with the highest stage matching degree is selected as the current attack stage.

[0047] In a specific embodiment, an attack behavior knowledge base containing a plurality of network attack types and corresponding behavior features is established, and the knowledge base predefines each stage of network attack, such as the investigation stage, the initial access stage, the privilege escalation stage, the data stealing stage, etc. For each attack stage, the knowledge base stores the state transition matrix, the historical interaction sequence sample and the standard transition probability distribution of the stage.

[0048] When suspicious behavior in the network is monitored, a relevant feature vector is extracted. The feature vector contains multiple dimensions, such as IP address access frequency, port scanning behavior, abnormal packet features, etc. Suppose the extracted feature vector is [0.8, 0.2, 0.5, 0.3], representing four different behavior feature indicators. From the knowledge base, a pre-defined state transition matrix corresponding to each attack stage is obtained, for example, the state transition matrix of the investigation stage stores the transition probabilities from one state to another. The feature vector is input into the state transition matrix, and the probability values of transitioning from the current state to each candidate state are calculated. For example, the calculation result shows that the probability of transitioning from the current state to state A is 0.6, the probability of transitioning to state B is 0.3, and the probability of transitioning to state C is 0.1, which constitutes the transition probability distribution of the current observation.

[0049] Further, historical interaction sequence samples of each attack stage are extracted from the attack behavior knowledge base, which record the past observed behavior sequences of attackers at each stage. Taking the investigation stage as an example, the historical samples may contain multiple interaction sequences such as "port scanning → vulnerability detection → information collection → port scanning". Based on these historical samples, a state transition directed graph is constructed, where the nodes represent different states and the edges represent the transition relationship between states. In the directed graph, a cycle path is identified, such as "port scanning → vulnerability detection → port scanning" forming a cycle. The cycle length and cycle frequency of each cycle path are calculated, where the cycle length is the number of states contained in the path, and the cycle frequency is the number of times the cycle appears in the historical samples. For example, a cycle length of 3 and a cycle frequency of 15 indicate that this cycle pattern appears frequently. Cycle paths with similar characteristics are grouped into the same cycle pattern group, for example, all cycles containing "port scanning" and "vulnerability detection" are grouped together. By analyzing the common characteristics of each cycle pattern group, core features are extracted as the cycle features of the attack stage. The possible cycle feature of the investigation stage is "frequent port scanning behavior and vulnerability detection appear alternately".

[0050] In analyzing the current observation transition probability distribution, the transition probability values are sorted, and the top few transition relationships with the highest probabilities are selected to form a state transition sequence. For example, if the observed behavior sequence is "port scanning → vulnerability detection → firewall testing → port scanning", the sequence is matched with the cycle features of each attack stage. The matching process calculates the number of state nodes in the state transition sequence that match the stage cycle features, and divides the total number of state nodes to obtain the cycle matching degree. Assuming that the sequence matches 3 nodes with the cycle features of the investigation stage, and the total number of nodes is 4, then the cycle matching degree is 0.75.

[0051] The probability distribution divergence between the current observation transition probability distribution and the standard transition probability distribution of each attack stage is calculated. The standard transition probability distribution is extracted from the knowledge base and represents the typical state transition probability pattern of each attack stage. Using a simplified information divergence calculation method, the divergence is quantified by comparing the differences in corresponding state transition probabilities between the two distributions. For example, the current observation transition probability distribution is [0.6, 0.3, 0.1], and the standard transition probability distribution of the investigation stage is [0.65, 0.25, 0.1]. The calculated divergence value is small, indicating that the two distributions have high similarity.

[0052] The probability distribution divergence and the cycle matching degree are weighted and fused to obtain the stage matching degree of each attack stage. The weighting process can use predefined weight coefficients, such as a cycle matching degree weight of 0.6 and a probability distribution divergence weight of 0.4. Assuming that the cycle matching degree of a certain attack behavior for the investigation stage is 0.75, and the similarity of the probability distribution divergence after conversion is 0.85, then the weighted and fused stage matching degree is 0.75x0.6+0.85x0.4=0.79. The matching degrees of the current observation behavior and all predefined attack stages are calculated, and the attack stage with the highest matching degree is selected as the current attack stage. If the matching degree of the investigation stage is 0.79, the matching degree of the initial access stage is 0.45, and the matching degree of the privilege escalation stage is 0.32, the system determines that the current attack is in the investigation stage.

[0053] In this embodiment, the current stage of the network attack can be accurately identified, providing an important basis for subsequent defense measures. The method of this embodiment combines state transition probability analysis and cycle feature matching, and can effectively deal with complex and variable network attack behaviors.

[0054] As shown in Figure 2 , a flowchart of attack stage determination based on state transition probability and cycle feature fusion is shown.

[0055] In an optional implementation, the cycle path is identified in the state transition directed graph, the cycle length and cycle frequency of the cycle path are calculated, the cycle path is divided into multiple cycle pattern groups, and the cycle pattern core features are extracted to determine the stage cycle features, including: In the state transition directed graph, the cycle path that starts from the starting state node and returns to the starting state node after passing through multiple intermediate state nodes is identified by a depth-first search algorithm. The sequence of state nodes and the sequence of state transition edges in the cycle path are extracted, the number of state nodes in the cycle path is calculated to determine the cycle length, and the occurrence frequency of the cycle path in the historical interaction sequence sample is calculated to determine the cycle frequency. The cycle length difference and the cycle frequency difference between each cycle path are calculated. When the cycle length difference is less than a preset length threshold and the cycle frequency difference is less than a preset frequency threshold, the cycle paths are divided into the same cycle mode group. The common state node subsequence and the common state transition edge subsequence of the cycle paths in each cycle mode group are extracted, and the cycle mode core feature is determined. The cycle mode core feature, the corresponding cycle length range and the cycle frequency range are combined to determine the stage cycle feature.

[0056] In a specific embodiment, in the state transition directed graph, each node represents a running state of the industrial control system, and the directed edge between the nodes represents the transition relationship from one state to another state. To identify the cycle path in the state transition process, a depth-first search algorithm is used to search the directed graph. The depth-first search starts from the starting state node and constantly penetrates along the directed edge while recording the visited nodes. When a successor node of the current node is found to be a visited node in the traversal process, it is indicated that a cycle path is found. For the industrial control system, such a cycle path usually reflects a periodic running mode, such as the on-off cycle of a device, the data acquisition cycle, etc.

[0057] The identification of the cycle path is specifically implemented as follows: a node access stack and a node access marking array are maintained. Initially, the starting state node is pushed into the stack and marked as visited. Subsequently, the recursive traversal process is entered, and each unvisited successor node of the current node is traversed. If a successor node is found to be in the access stack during the traversal process, it is indicated that a cycle path is found, and the path is determined by the node sequence from the successor node to the top node in the access stack. For example, in the industrial control system container environment monitoring, there is a state sequence: authentication request, authentication response, read request, read response, control request, control response, and read request. Through the depth-first traversal, the cycle path of "read request, read response, control request, control response, and read request" can be identified.

[0058] For the identified recurrent path, feature information needs to be extracted. The recurrent length is the number of state nodes contained in the recurrent path, which reflects the complexity of the recurrence. For the aforementioned example, the recurrent length is 5. The recurrent frequency refers to the number of times the recurrent path appears in the historical interaction sequence samples, which reflects the stability and importance of the recurrence. By statistical analysis of historical data, it is assumed that the recurrent path has appeared 15 times in the past 24 hours, and its recurrent frequency is 15. The complete representation of the recurrent path includes the state node sequence and the state transition edge sequence. The former records all the states passed in the recurrence, and the latter records the transition relationship between the states. For example, the state node sequence is [read request, read response, control request, control response, read request], and the state transition edge sequence is [(read request→read response), (read response→control request), (control request→control response), (control response→read request)].

[0059] In order to effectively induce recurrent patterns, the identified recurrent paths need to be grouped. The grouping basis is the recurrent length difference and the recurrent frequency difference. The recurrent length difference is the absolute value of the difference between the recurrent lengths of two recurrent paths, and the recurrent frequency difference is the absolute value of the difference between the recurrent frequencies of two recurrent paths. When the recurrent length difference of two recurrent paths is less than a preset length threshold (such as 2), and the recurrent frequency difference is less than a preset frequency threshold (such as 5), it is considered that the two recurrent paths belong to the same recurrent pattern group. The preset length threshold and the preset frequency threshold can be adjusted according to the actual application scene and requirements. Smaller threshold will produce more fine grouping, and larger threshold will make the grouping more extensive.

[0060] For the set of cyclic paths belonging to the same cyclic pattern group, the core feature of the cyclic pattern is determined by extracting its common state node sub-sequence and common state transition edge sub-sequence. The common state node sub-sequence refers to the sequence of state nodes appearing in all cyclic paths, which can be extracted by sequence alignment algorithm. The common state transition edge sub-sequence refers to the sequence of state transition relationships appearing in all cyclic paths. These two sub-sequences together constitute the core feature of the cyclic pattern, reflecting the essential content of the cyclic pattern. Take two cyclic paths in the industrial container environment as an example: path 1 is [read request, read response, control request, control response, read request], and path 2 is [read request, read response, state query request, state query response, control request, control response, read request]. The cycle lengths of the two paths are 5 and 7 respectively, with a difference of 2; the cycle frequencies are 15 and 12 respectively, with a difference of 3. If the preset length threshold is 2 and the preset frequency threshold is 5, the two paths can be divided into the same cyclic pattern group. Through sequence alignment, the extracted common state node sub-sequence is [read request, read response, control request, control response, read request], and the common state transition edge sub-sequence is [(read request→read response), (read response→...), (...→control request), (control request→control response), (control response→read request)], where "..." indicates the presence of other states in between.

[0061] The phase cycle feature is a combination of the core feature of the cyclic pattern and the corresponding cycle length range and cycle frequency range. The cycle length range is an interval consisting of the minimum cycle length and the maximum cycle length within the cyclic pattern group, and the cycle frequency range is an interval consisting of the minimum cycle frequency and the maximum cycle frequency within the cyclic pattern group. The phase cycle feature comprehensively describes the characteristics of the cyclic pattern, including its core content, complexity range, and stability range. In the foregoing example, the phase cycle feature can be represented as: the core feature is [read request→read response→...→control request→control response→read request], the cycle length range is [5, 7], and the cycle frequency range is [12, 15]. This feature indicates that the cyclic pattern takes data reading and control operations as the core, has moderate cycle complexity, and has high stability.

[0062] In the application scenario of security deception detection of industrial control containers, the behavior baseline of the normal operation of the industrial control system can be established by extracting and analyzing these stage cycle characteristics. When the cycle pattern in the actual operation process does not match the baseline characteristics, such as abnormal increase in cycle length, significant reduction in cycle frequency, change in core characteristics, etc., it may mean that the system has been attacked or an abnormal situation has occurred. For example, an attacker changes the normal running cycle by injecting malicious code into the container and performs unauthorized operations. By comparing the real-time monitored cycle characteristics with the pre-established normal cycle characteristic baseline, such security threats can be detected in a timely manner, and appropriate protection measures can be taken.

[0063] In an optional implementation, based on the current attack stage, the delay time parameter and the response template are determined to generate response data, and the simulation service instance is controlled to return the response data, which comprises: According to the current attack stage, the delay time parameter and the response template corresponding to the attack stage are extracted from the preset policy library; The adjustment field in the response template is parsed to obtain the data type and value constraint range of the adjustment field, the induction direction of the adjustment field is determined based on the attack characteristics of the current attack stage, and a boundary value is selected as an induced numerical value along the induction direction in the value constraint range; The initial value of the adjustment field is replaced by the induced numerical value, the initial values of the non-adjustment fields in the response template are kept unchanged, the response data containing the induced numerical value is generated, and the response sending time is calculated based on the current time and the delay time parameter; The simulation service instance is controlled to return the response data to the attack source at the response sending time.

[0064] In a specific implementation, when the industrial control system container environment detects potential attack behavior, the corresponding delay time parameter and response template need to be extracted from the preset policy library according to the current attack stage. The attack stage usually includes the reconnaissance stage, the access control stage, the control hijacking stage, etc. The preset policy library is a structured storage body containing a set of response strategies for different attack stages. Each strategy set contains at least two key parameters: delay time parameter and response template. The delay time parameter defines the time characteristics of the system response, including the basic delay value, the random fluctuation range, etc. The response template is a pre-designed data structure template, which contains multiple data fields and their default values. These fields are divided into two categories: adjustment fields and non-adjustment fields. Taking the industrial control protocol Modbus as an example, when it is detected that the attack is in the reconnaissance stage, the delay time parameter that the strategy library may extract is the basic delay of 200 milliseconds and the random fluctuation range of plus or minus 50 milliseconds; the response template may contain fields such as function code, starting address, data length, data content, etc., among which the data content is marked as an adjustment field.

[0065] For the response template extracted from the policy library, the adjustment field needs to be parsed to obtain the data type and value constraint range of the adjustment field. The data type can be integer, floating point, Boolean, or string, etc., and the value constraint range defines the minimum and maximum values allowed for the field. In the industrial control environment, different types of data points have their specific reasonable value ranges, for example, the value range of a temperature sensor can be -40 to 100 degrees Celsius, and the value range of a pressure sensor can be 0 to 16 megapascals. Based on the attack characteristics of the current attack stage, the induction direction of the adjustment field is determined, which can be upward, downward, or a specific value. Attack characteristics refer to the behavior characteristics exhibited by the attacker at the current stage, such as frequently querying specific registers, attempting to modify specific parameters, etc. If the attacker shows interest in high temperature data, the induction direction is set to upward, guiding the attacker to continue probing higher temperature thresholds; if the attacker attempts to lower the pressure threshold, the induction direction can be set to downward, making the attacker mistakenly believe that the pressure control has been breached. After determining the induction direction, a boundary value is selected as the induction value within the value constraint range along the direction. The boundary value refers to a value close to the limit within the reasonable range, which neither significantly violates the physical law to arouse the attacker's vigilance, nor can induce the attacker to continue to probe in a specific direction. For example, if the normal working range of the temperature sensor is 20 to 80 degrees Celsius, the current value is 50 degrees Celsius, and the attacker shows interest in high temperature, 75 degrees Celsius can be selected as the induction value, which is close to the upper boundary but still within the reasonable range.

[0066] After determining the induction value, the initial value of the adjustment field is replaced with the induction value, while keeping the initial values of the non-adjustment fields in the response template unchanged, generating response data containing the induction value. Non-adjustment fields usually include protocol headers, function codes, checksums, and other standard fields, keeping the initial values of these fields unchanged ensures the legitimacy and consistency of the response data. For the adjustment field, appropriate format conversion is performed according to its data type to ensure that the representation of the induction value in the data packet conforms to the protocol specification. For example, if the adjustment field is a 16-bit unsigned integer and the induction value is 75, 75 needs to be converted to the corresponding two-byte hexadecimal representation. After generating the response data, the response sending time is calculated based on the current time and the delay time parameter. The response sending time is equal to the current time plus the base delay value plus a random value within the random fluctuation range. Introducing random delay can make the system response more natural and avoid being identified by the attacker as fraudulent behavior through fixed time characteristics. For example, if the current time is 10:15:30.500, the base delay is 200 milliseconds, the random fluctuation range is plus or minus 50 milliseconds, and the randomly generated fluctuation value is +30 milliseconds, then the response sending time is 10:15:30.730.

[0067] The control simulation service instance returns the response data to the attack source at the calculated response sending moment. The simulation service instance is a simulation program running in a container environment and can simulate the communication behavior of an industrial control device. By accurately controlling the content and sending time of the response data, a realistic deception environment can be created, making it difficult for the attacker to distinguish between true and false. At the same time, the simulation service instance records all interaction histories, including the received request data and the sent response data, which will be used for subsequent attack analysis and strategy optimization.

[0068] Exemplarily, the industrial control container environment detects that the attacker is in the reconnaissance stage and is frequently querying the current temperature value of the temperature controller. The strategy corresponding to the reconnaissance stage is extracted from the preset strategy library, and the delay time parameter is 200 milliseconds of basic delay and a random fluctuation range of plus or minus 50 milliseconds; the response template is a Modbus read and hold register response, including function code (0x03), byte number (0x04), data content (current 0x01A4, i.e. 420, representing 42.0 degrees Celsius), CRC check and other fields, wherein the data content is marked as an adjustment field. Analyzing the adjustment field finds that the data type thereof is a temperature value with one decimal place, and the value constraint range is -40.0 to 100.0 degrees Celsius. Based on the characteristics that the attacker frequently queries the temperature value and attempts to query a higher temperature range for multiple times, it is determined that the induction direction is upward. Within the value constraint range, a boundary value of 95.0 degrees Celsius (0x03B6) is selected as the induction value in the upward direction. The initial value 0x01A4 of the adjustment field is replaced by the induction value 0x03B6, and the function code, byte number, CRC check and other non-adjustment fields remain unchanged to generate a complete response data packet. The current time is 14:22:45.300, and the calculated random fluctuation value is +25 milliseconds, so the response sending moment is 14:22:45.525. The simulation service instance returns the generated response data to the attack source at this moment and records this interaction.

[0069] In this embodiment, the deception system presents the attacker with a sensor reading close to the high temperature limit, inducing the attacker to further attempt to increase the temperature setting value or trigger the high temperature alarm mechanism, thereby exposing more attack intentions. At the same time, the carefully designed delay time makes the response behavior conform to the characteristics of the real device, enhancing the deception effect. This industrial control security deception detection method based on container technology can dynamically adapt to different attack stages, generate targeted deception responses, and effectively guide the attack behavior into a controllable range, providing a new technical means for industrial control system security protection.

[0070] The industrial control security deception detection system based on container technology in the embodiment of the application comprises: The first unit is configured to obtain an access request of an industrial control system, and when a preset abnormal behavior determination condition is met, direct the access request to a simulation service instance in a container environment. The second unit is configured to extract multiple interaction operations of the simulation service instance, map the interaction operations into nodes in a multi-layer directed graph and establish directed edges carrying transition weights, count weighted connection degrees of each node based on the transition weights, and calculate branch entropy values; The third unit is configured to parse control instructions in the interaction operations and extract parameter fields, compare the parameter fields with predefined data types and value ranges, construct a parameter dependency graph and track an influence propagation path, calculate a semantic deviation degree, and combine the branch entropy values and the semantic deviation degree into a feature vector; The fourth unit is configured to input the feature vector into a state transition matrix to calculate transition probability values, extract stage cycle characteristics and standard transition probability distributions of each attack stage from a preset attack behavior knowledge base, and determine the current attack stage based on weighted fusion of cycle matching degrees and probability distribution divergences; The fifth unit is configured to determine a delay time parameter and generate response data based on a response template based on the current attack stage, and control the simulation service instance to return the response data; The sixth unit is configured to isolate network access requests based on the current attack stage.

[0071] In a third aspect, an electronic device is provided, including: a processor; a memory for storing processor-executable instructions; The processor is configured to invoke the instructions stored in the memory to execute the method described above.

[0072] In a fourth aspect, a computer-readable storage medium is provided, which stores computer program instructions, and the computer program instructions are executed by a processor to implement the method described above.

[0073] The present application can be a method, device, system and / or computer program product. The computer program product can include a computer readable storage medium having computer readable program instructions stored therein, which are used to perform various aspects of the present application.

[0074] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for detecting industrial control security deception based on container technology, characterized in that, The method comprises the following steps: Obtaining an access request of an industrial control system, and when a preset abnormal behavior judgment condition is met, guiding the access request to a simulation service instance in a container environment; Extracting multiple interaction operations of the simulation service instance, mapping the interaction operations into nodes in a multi-layer directed graph and establishing directed edges carrying transition weights, calculating weighted connection degrees of each node based on the transition weights, and calculating branch entropy values; Analyzing control instructions in the interaction operations and extracting parameter fields, comparing the parameter fields with predefined data types and value ranges, constructing a parameter dependency graph and tracking an influence propagation path, calculating a semantic deviation degree, and synthesizing the branch entropy values and the semantic deviation degree into a feature vector; Inputting the feature vector into a state transition matrix to calculate transition probability values, extracting stage cycle characteristics and standard transition probability distributions of each attack stage from a preset attack behavior knowledge base, determining the current attack stage based on cycle matching degrees and probability distribution divergences; Based on the current attack stage, determining a delay time parameter and generating response data based on a response template, and controlling the simulation service instance to return the response data; Based on the current attack stage, implementing isolation on the network access request.

2. The method of claim 1, wherein, Extracting multiple interaction operations of the simulation service instance, mapping the interaction operations into nodes in a multi-layer directed graph and establishing directed edges carrying transition weights, calculating weighted connection degrees of each node based on the transition weights, and calculating branch entropy values include: Analyzing network data packets of each interaction operation received by the simulation service instance, extracting the timestamp, operation type identifier and protocol level identifier of each interaction operation, sorting each interaction operation according to the timestamp, dividing each interaction operation into application layer operations and transport layer operations based on the protocol level identifier, and mapping the sorted each interaction operation into nodes in a multi-layer directed graph; Traverse each node in the multi-layer directed graph, when the timestamp of the current sequence node is earlier than that of the subsequent node, extract the operation type identifier combination of the previous sequence node and the subsequent node, query a preset operation transition constraint table to determine whether the operation type identifier combination constitutes a valid transition path, and when it constitutes a valid transition path, establish a directed edge carrying a transition weight between the previous sequence node and the subsequent node; Taking each node in the multi-layer directed graph as a target node, counting the number of directed edges pointing to the target node to determine the number of predecessor nodes, counting the number of directed edges pointed out by the target node to determine the number of successor nodes, and weighting and accumulating the number of predecessor nodes and the number of successor nodes based on the corresponding transition weights to obtain the weighted connection degree of each node; Based on the ratio of the weighted connection degree of each node to the sum of the weighted connection degrees of all nodes, determine the probability distribution of each node, and calculate the information entropy based on the probability distribution to determine the branch entropy value of the operation sequence.

3. The method of claim 1, wherein, Analyzing control instructions in the interaction operations and extracting parameter fields, comparing the parameter fields with predefined data types and value ranges, constructing a parameter dependency graph and tracking an influence propagation path, calculating a semantic deviation degree, and synthesizing the branch entropy values and the semantic deviation degree into a feature vector include: The control instructions in each interaction operation are analyzed, the instruction operation code and parameter field are extracted, the corresponding parameter definition rule is queried from the industrial protocol specification library, the pre-defined data type, the pre-defined value range and the constraint relationship between parameters are obtained; The actual data type of the parameter field is matched and judged with the pre-defined data type, when the actual data type is inconsistent with the pre-defined data type, it is marked as data type deviation, the actual value of the parameter field is interval judged with the pre-defined value range, when the actual value exceeds the pre-defined value range, it is marked as value range deviation, the total number of data type deviation and value range deviation is counted to determine the parameter deviation number; Based on the constraint relationship between parameters, a parameter dependency graph is constructed, and propagation simulation is performed along the parameter dependency graph from the deviation source node to determine the influence propagation path, and the influence diffusion degree is calculated based on the influence propagation path; Based on the parameter deviation number and the total number of parameter fields, the basic deviation rate is calculated, based on the influence diffusion degree of each parameter deviation field and the total number of parameter nodes in the parameter dependency graph, the diffusion deviation rate is calculated, and the semantic deviation degree is obtained by fusing the basic deviation rate and the diffusion deviation rate; The branch entropy value and the semantic deviation degree of the operation sequence are normalized and combined to construct a feature vector.

4. The method of claim 3, wherein, Based on the constraint relationship between parameters, a parameter dependency graph is constructed, and propagation simulation is performed along the parameter dependency graph from the deviation source node to determine the influence propagation path, and the influence diffusion degree is calculated based on the influence propagation path; The constraint relationship between parameters is analyzed, the numerical correlation constraint and the time sequence constraint between parameter fields are extracted, each parameter field is taken as a parameter node, when there is a numerical correlation constraint between the first parameter field and the second parameter field, an associated edge is established in the direction from the first parameter field to the second parameter field and the constraint condition is marked, when there is a time sequence constraint between the first parameter field and the second parameter field, a time sequence edge is established and the time sequence interval is marked, and a parameter dependency graph containing associated edges and time sequence edges is constructed; In the parameter dependency graph, the parameter field where the data type deviation or the value range deviation occurs is located to determine the deviation source node, from each deviation source node, propagation simulation is performed along the associated edge and the time sequence edge, in the propagation process, the constraint condition marked on each edge is extracted, it is judged whether the downstream parameter node triggers constraint violation when the current deviation source node deviates, when the downstream parameter node triggers constraint violation, the downstream parameter node is marked as an affected node and continues to propagate downstream, when the downstream parameter node does not trigger constraint violation, the propagation branch is terminated, the propagation link from the deviation source node to each affected node is recorded, and the influence propagation path is determined; The number of affected nodes corresponding to each deviation source node is counted, the number of edges passed in each influence propagation path is extracted as the propagation depth, and the influence diffusion degree of each deviation source node is calculated based on the number of affected nodes and the propagation depth.

5. The method of claim 1, wherein, The feature vector is input into a state transition matrix to calculate a transition probability value, the stage cycle characteristics and the standard transition probability distribution of each attack stage are extracted from a preset attack behavior knowledge base, and the current attack stage is determined based on the cycle matching degree and the probability distribution divergence weighted fusion. extract a predefined attack stage sequence and a state transition matrix corresponding to each attack stage from a preset attack behavior knowledge base, input the feature vector into the state transition matrix, calculate transition probability values from a current state to each candidate state, and construct a current observation transition probability distribution; extract a historical interaction sequence sample of each attack stage from the attack behavior knowledge base, construct a state transition directed graph of each attack stage, identify a cycle path in the state transition directed graph, calculate a cycle length and a cycle frequency of the cycle path, divide the cycle path into a plurality of cycle pattern groups, and extract a cycle pattern core feature to determine a stage cycle feature; analyze a state transition sequence corresponding to the current observation transition probability distribution, perform pattern matching between the state transition sequence and the stage cycle feature of each attack stage, calculate a ratio of a number of matched state nodes to a total number of state nodes in the state transition sequence, and determine a cycle matching degree; calculate a probability distribution divergence between the current observation transition probability distribution and a standard transition probability distribution of each attack stage, weight and fuse the probability distribution divergence and the cycle matching degree of the corresponding attack stage to obtain a stage matching degree, and select an attack stage with the highest stage matching degree as a current attack stage.

6. The method of claim 5, wherein, In the state transition directed graph, a cycle path is identified, a cycle length and a cycle frequency of the cycle path are calculated, the cycle path is divided into a plurality of cycle pattern groups, and a cycle pattern core feature is extracted to determine a stage cycle feature, including: In the state transition directed graph, a cycle path is identified by a depth-first search algorithm, a sequence of state nodes and a sequence of state transition edges in the cycle path are extracted, a cycle length is calculated by counting the number of state nodes in the cycle path, and a cycle frequency is calculated by counting the number of occurrences of the cycle path in the historical interaction sequence sample; calculate the cycle length difference and the cycle frequency difference between each cycle path, when the cycle length difference is less than a preset length threshold and the cycle frequency difference is less than a preset frequency threshold, divide the cycle path into the same cycle pattern group, extract a common state node subsequence and a common state transition edge subsequence of the cycle path in each cycle pattern group, determine the cycle pattern core feature, and combine the cycle pattern core feature with the corresponding cycle length range and cycle frequency range to determine the stage cycle feature.

7. The method of claim 1, wherein, Based on the current attack stage, a delay time parameter and a response template are determined to generate response data, and a simulation service instance is controlled to return the response data, including: According to the current attack stage, extract a delay time parameter and a response template corresponding to the attack stage from a preset strategy library; analyze the adjustment field in the response template, obtain the data type and the value constraint range of the adjustment field, determine the induction direction of the adjustment field based on the attack feature of the current attack stage, and select a boundary value as an induced value along the induction direction in the value constraint range; replace the initial value of the adjustment field with the induced value, keep the initial value of the non-adjustment field in the response template unchanged, generate response data containing the induced value, calculate the response sending time based on the current time and the delay time parameter; The control simulation service instance returns the response data to the attack source at the response sending moment.

8. A container technology-based industrial control security deception detection system for implementing the method of any one of the preceding claims 1-7, characterized by, The method comprises the steps of: The first unit is configured to obtain an access request of an industrial control system, and when a preset abnormal behavior judgment condition is met, direct the access request to a simulation service instance in a container environment. The second unit is configured to extract multiple interactive operations of the simulation service instance, map the interactive operations as nodes in a multi-layer directed graph, and establish directed edges carrying transfer weights, calculate weighted connection degrees of each node based on the transfer weights, and calculate branch entropy values. The third unit is configured to analyze control instructions in the interactive operations and extract parameter fields, compare the parameter fields with predefined data types and value ranges, construct a parameter dependency graph and track an influence propagation path, calculate a semantic deviation degree, and synthesize the branch entropy values and the semantic deviation degree into a feature vector. The fourth unit is configured to input the feature vector into a state transition matrix to calculate a transfer probability value, extract stage cycle characteristics and standard transfer probability distributions of each attack stage from a preset attack behavior knowledge base, determine a current attack stage based on a cycle matching degree and a probability distribution divergence weighted fusion. The fifth unit is configured to determine a delay time parameter and generate response data based on the current attack stage, and control the simulation service instance to return the response data. The sixth unit is configured to isolate network access requests based on the current attack stage.

9. An electronic device, comprising: The method comprises the steps of: A processor; A memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method of any one of claims 1 to 7.

10. A computer-readable storage medium having stored thereon computer program instructions, wherein, The computer program instructions are executed by the processor to implement the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Fraud detection and analysis

    CN105556552A

  • Intranet security protection system and method based on dynamic deception type parallel network

    CN115987531A

  • Deception defense method and device based on reinforcement learning high attack and defense interaction in multi-honeypot scene

    CN117938473A

  • Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

    CN120639470A

  • Attack detection and countermeasure identification system

    US20230297672A1

Cited By

  • Internal and external network cooperative access control and security isolation system, method and device based on FTTR and medium

    CN122316801A