A cluster vulnerability mining method based on industrial control systems
By establishing independent databases and simplex communication in the industrial control system, and simulating the vulnerability environment for detection and repair, the problem of insufficient flexibility of cluster vulnerability mining methods is solved, and comprehensive exploitation of vulnerabilities and system security guarantees are achieved.
Patent Information
- Application Number
- CN202111391302.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-23
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2041-11-23
AI Technical Summary
The existing industrial control system cluster vulnerability mining methods lack flexibility and cannot fully respond to attacks and chain reactions caused by vulnerabilities, and attackers may continue to attack through vulnerabilities.
Establish an independent database and set up simplex communication, simulate the industrial system environment for vulnerability detection and repair, use the combination of simplex communication ports and full duplex communication ports to prevent data leakage and collect attack data, and restore data and in-depth mining through backup databases.
On the premise of ensuring system security, we will fully understand the attacker's attack methods, prevent data leakage, collect more attack data, provide a more flexible vulnerability mining foundation, and ensure the security of industrial systems.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of industrial control systems, and in particular to a cluster vulnerability mining method based on industrial control systems. Background Art
[0002] Industrial control systems are technologies that use computers and network technologies to control increasingly complex industrial systems in industrial production. Early industrial control systems were mainly controlled centrally by computers. However, with the continuous development of the times, cluster technology, which controls the entire industrial system through groups of independent computers interconnected by high-speed networks, has gradually attracted people's attention.
[0003] Compared with early industrial control systems, cluster systems can improve the performance of the overall control system at a lower cost while also meeting high returns. However, in actual work, the emergence of vulnerabilities is often unpredictable. When a vulnerability occurs, the cluster will shut down the server with the vulnerability and control other servers to take over the server with the vulnerability. The vulnerability is often dealt with shortly after it occurs. However, some attackers will use the vulnerability to carry out a series of attack operations. If the discovered vulnerability is blocked and eliminated at the beginning, it is often impossible to predict the attacker's subsequent attacks on the vulnerability. Calculating the attacker's attack methods through simple calculations also lacks a certain degree of flexibility and cannot respond more comprehensively to the chain reaction caused by the vulnerability. Summary of the Invention
[0004] Based on the technical problems existing in the background technology, the present invention proposes a cluster vulnerability mining method based on industrial control systems, which has the characteristics of more comprehensive and flexible vulnerability mining, and solves the problem that most existing vulnerability mining methods rely on calculations and lack a certain degree of flexibility.
[0005] The present invention provides the following technical solutions:
[0006] A cluster vulnerability mining method based on an industrial control system includes the following steps:
[0007] S1. Establish a database independent of the cluster to record the work instructions and operation logic received by the node system and communication system in the cluster in the industrial control system;
[0008] S2. The cluster runs normally, and the monitoring module repeatedly detects vulnerabilities during operation.
[0009] S3. The monitoring module in the cluster is responsible for detecting vulnerabilities in the servers where applications are running. After confirmation by the system management layer in the cluster, the server with the vulnerability is shut down and the remaining servers are controlled to take over.
[0010] S4. Connect the vulnerable server to an independent database through the system management layer in the cluster. Set the communication between the network server and the vulnerable server to simplex communication, and prohibit the vulnerable server from feeding information back to the network server.
[0011] S5. The vulnerable server continues to work in a simulated environment in an independent database, and the system management layer in the cluster records the damage caused by the vulnerability to the database.
[0012] S6. When the vulnerability stops damaging the data in the database, the system management will alert the staff, disconnect the independent database from the network server, and record the process of the vulnerability damaging the data;
[0013] S7. The staff will patch the vulnerability and restore the data recorded in the independent database;
[0014] S8. The data damage path of the vulnerability is further calculated in the vulnerability mining module, and deep mining is carried out in combination with the hacker attack data in the existing database. The calculated data is sent to the system management layer to repair the vulnerability.
[0015] Furthermore, the number of independent databases in step S1 is two, and the other independent database is a backup database of the independent database in S1.
[0016] Through the above technical solution, when data in one database is damaged, the data in the damaged database can be compared and restored using the data in the other database, which facilitates subsequent maintenance.
[0017] Furthermore, the server where the vulnerability occurs in step S4 is provided with a simplex communication port and a full-duplex communication port, and the simplex communication port and the full-duplex communication port are connected to the external network through a one-to-two splitter, and when it is necessary to switch to simplex communication, the connection between the full-duplex communication port and the server needs to be disconnected.
[0018] The above technical solution can prevent attackers from obtaining real data when attacking independent databases, thereby preventing confidential data from being leaked.
[0019] Furthermore, the server where the vulnerability occurs in step S4 is provided with two simplex communication ports with opposite communication directions and one full-duplex port, and the two simplex communication ports and the full-duplex communication port are connected to the external network through a one-to-four optical splitter. When it is necessary to switch to simplex communication, the connection between the full-duplex communication port and the server needs to be disconnected, and at the same time, another simplex communication port that only allows the independent database to communicate with the external network sends a simulated data packet to the external network.
[0020] Through the above technical solution, when an attacker attacks the content in an independent database through a vulnerability, the system can also feed back a false simulation signal to the attacker, preventing the attacker from stopping the attack after noticing no feedback, ensuring that the attacker can carry out the attack operation more completely. The staff can also collect more attack data sent by the attacker through the vulnerability, and fully understand the security risks of the vulnerability, thereby providing a basis for in-depth mining of the vulnerability.
[0021] Compared with the prior art, the present invention has the following beneficial effects:
[0022] Through the independent database provided, the present invention can simulate the actual working conditions of the industrial system in a virtual environment, thereby allowing attackers to continue to attack the virtual working system through vulnerabilities and understand the attacker's attack methods. At the same time, the simplex communication provided can also ensure that the device attributes and various parameters of various devices in the industrial system will not be leaked. While ensuring the security of the working system, the real intentions of the attacker can be understood, thereby more flexibly exploring more hidden dangers of vulnerabilities and ensuring the security of the industrial system.
[0023] The present invention provides two simplex communication ports, so that when an attacker attacks the content in an independent database through a vulnerability, the system can also feed back a false analog signal to the attacker, preventing the attacker from stopping the attack after noticing that there is no feedback, ensuring that the attacker can carry out the attack operation more completely. The staff can also collect more attack data sent by the attacker through the vulnerability, and fully understand the security risks of the vulnerability, thereby providing a basis for in-depth mining of the vulnerability. DETAILED DESCRIPTION
[0024] The present invention is further described below with reference to the examples. Example 1
[0025] A cluster vulnerability mining method based on an industrial control system includes the following steps:
[0026] S1. Establish a database independent of the cluster to record the work instructions and operating logic received by the node system and communication system in the cluster in the industrial control system.
[0027] S2. The cluster runs normally, and during operation, the monitoring module repeatedly detects vulnerabilities.
[0028] S3. The monitoring module in the cluster is responsible for detecting vulnerabilities in the servers where the applications are running. After confirmation by the system management layer in the cluster, the server with the vulnerability is shut down and the remaining servers are controlled to take over.
[0029] S4. Connect the vulnerable server to an independent database through the system management layer in the cluster, and set the communication between the network server and the vulnerable server to simplex communication, prohibiting the vulnerable server from feeding back information to the network server.
[0030] S5. The server with the vulnerability continues to work in an environment simulated in an independent database, and the damage caused by the vulnerability to the database is recorded through the system management layer in the cluster.
[0031] S6. When the vulnerability stops damaging the data in the database, the system management layer will remind the staff, disconnect the independent database from the network server, and record the process of the vulnerability damaging the data.
[0032] S7. The staff will patch the vulnerabilities and restore the data recorded in the independent database.
[0033] S8. The data damage path of the vulnerability is further calculated in the vulnerability mining module, and deep mining is carried out in combination with the hacker attack data in the existing database. The calculated data is sent to the system management layer to repair the vulnerability.
[0034] Through the independent database, the actual working conditions of the industrial system can be simulated in a virtual environment, allowing attackers to continue to attack the virtual working system through vulnerabilities and understand the attacker's attack methods. At the same time, the simplex communication can also ensure that the device attributes and various parameters of various devices in the industrial system will not be leaked. While ensuring the security of the working system, the real intentions of the attacker can be understood, so as to more flexibly explore more hidden dangers of vulnerabilities and ensure the security of the industrial system.
[0035] Furthermore, the number of independent databases in S1 is two, and the other independent database is a backup database of the independent database in S1.
[0036] By setting up two independent databases, when the data in one database is damaged, the data in the other database can be used to compare and recover the data in the damaged database, which facilitates subsequent maintenance.
[0037] Furthermore, the server in S4 where the vulnerability occurs is equipped with a simplex communication port and a full-duplex communication port, and the simplex communication port and the full-duplex communication port are connected to the external network through a one-to-two splitter, and when it is necessary to switch to simplex communication, the connection between the full-duplex communication port and the server needs to be disconnected.
[0038] The simplex communication can prevent attackers from obtaining real data when attacking independent databases, thus preventing confidential data from being leaked. Example 2
[0039] Different from Example 1, the server where the vulnerability occurs in S4 is provided with two simplex communication ports with opposite communication directions and one full-duplex port, and the two simplex communication ports and the full-duplex communication port are connected to the external network through a one-to-four optical splitter. When it is necessary to switch to simplex communication, the connection between the full-duplex communication port and the server needs to be disconnected, and at the same time, another simplex communication port that only allows the independent database to communicate with the external network sends a simulated data packet to the external network.
[0040] Through the two simplex communication ports, when an attacker attacks the content in an independent database through a vulnerability, the system can also feed back a false analog signal to the attacker, preventing the attacker from stopping the attack after noticing no feedback, ensuring that the attacker can carry out the attack more completely. The staff can also collect more attack data sent by the attacker through the vulnerability, and fully understand the security risks of the vulnerability, thus providing a basis for in-depth exploration of the vulnerability.
[0041] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.
Claims
1. A cluster vulnerability mining method based on industrial control systems, characterized in that: The following steps are involved: S1. Establish a database independent of the cluster to record the work instructions and operation logic received by the node system and communication system in the cluster in the industrial control system; S2. The cluster runs normally, and the monitoring module repeatedly detects vulnerabilities during operation. S3: The monitoring module in the cluster discovers a vulnerability in a running server. After confirmation by the system management layer in the cluster, the system management layer shuts down the vulnerable server and controls the remaining servers to take over. S4. Connect the vulnerable server to an independent database through the system management layer in the cluster. Set the communication between the network server and the vulnerable server to simplex communication, and prohibit the vulnerable server from feeding information back to the network server. S5. The vulnerable server continues to work in a simulated environment in an independent database, and the system management layer in the cluster records the damage caused by the vulnerability to the database. S6. When the vulnerability stops damaging the data in the database, the system management will alert the staff, disconnect the independent database from the network server, and record the process of the vulnerability damaging the data; S7. The staff will patch the vulnerability and restore the data recorded in the independent database; S8. The data damage path of the vulnerability is further calculated in the vulnerability mining module, and deep mining is carried out in combination with the hacker attack data in the existing database. The calculated data is sent to the system management layer to repair the vulnerability.
2. The cluster vulnerability mining method based on industrial control systems according to claim 1 is characterized in that: The number of independent databases in S1 is two, and the other independent database is a backup database of the independent database in S1.
3. The cluster vulnerability mining method based on industrial control systems according to claim 1 is characterized in that: The server in S4 where the vulnerability occurs is equipped with a simplex communication port and a full-duplex communication port, and the simplex communication port and the full-duplex communication port are connected to the external network through a one-to-two splitter. When it is necessary to switch to simplex communication, the connection between the full-duplex communication port and the server needs to be disconnected.
4. The cluster vulnerability mining method based on industrial control systems according to claim 1 is characterized in that: The server where the vulnerability occurs in S4 is equipped with two simplex communication ports with opposite communication directions and one full-duplex port. The two simplex communication ports and the full-duplex communication port are connected to the external network through a one-to-four optical splitter. When it is necessary to switch to simplex communication, the connection between the full-duplex communication port and the server must be disconnected. At the same time, another simplex communication port that only allows independent databases to communicate with the external network sends a simulated data packet to the external network.
Citation Information
Patent Citations
Method for capturing computer software vulnerability exploitation and system
CN102521542A
Industrial control system vulnerability trend analysis and early warning method and system
CN109818985A