A configuration type safety protection system based on hub power plant industrial control system
Patent Information
- Application Number
- CN202111410239.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-25
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2041-11-25
AI Technical Summary
[0002]在火电厂传统安全防护体系中,缺乏对工业控制网络用户操作、工控网络行为、指令下发的审计措施,导致安全事故分析取证困难
[0072]本发明根据电力监控系统网络的安全现状并结合工控系统运行环境相对稳定,系统更新频率较低的特点,结合GB/T 22239-2019《信息安全技术网络安全等级保护基本要求》,采用基于“白名单”机制的工业控制系统网络安全“白环境”解决方案,通过对工控网络流量、工控主机状态等进行监控,收集并分析工控网络数据及软件运行状态,建立工控系统正常工作环境下的安全状态基线和模型,进而构筑工业控制系统的网络安全“白环境”,确保:
Smart Images

Figure CN114418261B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security protection technology for power plant industrial control systems, and in particular to a configurable security protection system based on the industrial control system of a hub power plant. Background Technology
[0002] Traditional safety protection systems in thermal power plants lack auditing measures for user operations, network behavior, and command issuance on industrial control networks, making it difficult to analyze and collect evidence in the event of a safety accident. Furthermore, some industrial control networks lack auditing capabilities, and others with log auditing functions cannot enable this feature due to system performance requirements.
[0003] Furthermore, while there are numerous existing solutions for protecting industrial control systems, they all target conventional industrial control systems and implement conventional protection measures. Auxiliary control systems in thermal power plants have unique characteristics and specific security requirements, but there has never been a unified standard for their protection solutions. This invention provides a robust security protection technology and solution, offering comprehensive security protection for auxiliary control systems.
[0004] Therefore, it is necessary to carry out targeted security hardening based on the unique communication requirements of the system and the potential security vulnerabilities, form an effective defense against current attack methods, and form a new configuration-based security protection system based on the hub power plant industrial control system. This will realize a network security protection system for thermal power plant industrial networks that can prevent high-intensity attacks and APT attacks, and improve the construction of the power plant industrial control security protection capability system. Summary of the Invention
[0005] To address the problems existing in the prior art, this invention provides the following technical solution: based on the latest trends in network attack and defense technologies and standards at home and abroad, combined with the characteristics of industrial control systems, engineering practices, and user experience, it balances the relationship between the security compliance and practicality of industrial control systems. This invention provides an industrial control network security monitoring and auditing platform for industrial control network traffic, aiming to strengthen and enhance the security audit and protection capabilities of industrial control networks. It enables real-time detection and alarming of abnormal behavior, protocol attacks, and critical events in industrial control networks, timely discovery of internal violations, and provides detailed records for post-incident investigation and evidence collection.
[0006] This invention provides a configuration-based security protection system based on the industrial control system of a hub power plant, comprising:
[0007] The system includes a DCS system security protection subsystem, an NCS system security protection subsystem, an auxiliary control system security protection subsystem, an electricity billing system security protection subsystem, a chemical water treatment, ash export and water purification plant system security protection subsystem, and a production control area security situation awareness subsystem.
[0008] Each of the aforementioned subsystems includes:
[0009] The communication network security protection subsystem is used to ensure the security of communication processes and communication data in industrial control systems.
[0010] The security zone boundary security protection subsystem is used to inspect or restrict internal and external network behavior, detect, prevent and restrict network attacks, analyze network behavior, record and alarm attack information, conduct security audits and verify the trustworthiness of boundary devices.
[0011] The secure computing environment security protection subsystem is used for user authentication, regular backup of audit logs, detection, identification, and alarm for intrusion behaviors and viruses at critical nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup; and
[0012] The security management center is used by system administrators to perform system management operations and audit operation records through commands or an interface, and by audit administrators to perform security audit operations and audit operation records through commands or an interface. It allows for the setting of specific management areas and security information transmission paths to control security devices or components distributed throughout the network; centralized monitoring of the operational status of network links, security devices, network equipment, and servers; aggregation and analysis of device audit data; management of security policies, malicious code, and patch upgrades; and detection, identification, and alerting of security events in the network.
[0013] Preferably, the DCS system security protection subsystem includes:
[0014] DCS system industrial control security monitoring and auditing equipment is deployed in the DCS system of each unit to realize network traffic auditing and abnormal behavior alarm;
[0015] DCS System Industrial Control Host Guardian is deployed on industrial control hosts, servers, interface machines, and other devices in various DCS systems to protect against malicious code and manage peripheral ports.
[0016] The DCS system network threat awareness system is deployed at the network boundary of the DCS system production control area to detect anomalies, intrusion behaviors, and especially analyze new types of network attacks.
[0017] The DCS system security operation and maintenance management system is deployed within the DCS system security management area to achieve identity authentication, access control, and security auditing of user operation behaviors in the production control area.
[0018] The DCS system unified security management system is deployed within the DCS system security management area to achieve unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0019] The DCS system log auditing and analysis system is deployed in the DCS system security management area to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events.
[0020] The DCS system vulnerability scanning system is deployed in the DCS system security management area to perform vulnerability scanning and control on existing equipment, and to scan and eliminate vulnerabilities in new network access equipment in advance to reduce network access risks.
[0021] The DCS system network security access control system is deployed within the DCS system security management area to check or restrict unauthorized devices from connecting to the internal network; and to perform security checks on devices that need to access the network, allowing them to access the internal network only after the checks are passed.
[0022] The DCS system industrial firewall provides boundary isolation for the security management area, and also for the boundary isolation between units, strengthening security boundary access control capabilities and prohibiting unauthorized connection requests.
[0023] Preferably, the NCS system security protection subsystem includes:
[0024] NCS system industrial control security monitoring and auditing equipment enables network traffic auditing and abnormal behavior alarms;
[0025] NCS System Industrial Control Host Guardian is deployed on industrial control hosts, servers, interface machines, and other devices in the NCS system to protect against malicious code and manage peripheral ports.
[0026] The NCS system intrusion detection system is deployed at the network boundary of the NCS system production control area to detect anomalies and intrusion behaviors.
[0027] The NCS system security operation and maintenance management system is deployed within the NCS system security management area to realize identity authentication, access control and security auditing of user operation behavior in the production control area;
[0028] The NCS Unified Security Management System is deployed within the NCS system security management area to achieve unified management of security protection devices, systems, and host security policies, as well as unified collection and storage of security device and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0029] The NCS system log auditing and analysis system is deployed in the NCS system security management area to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events.
[0030] The NCS system network security access control system is deployed within the NCS system security management area to check or restrict unauthorized devices from connecting to the internal network; it also performs security checks on devices that need to access the network, and allows them to access the internal network only after the checks are passed.
[0031] The NCS system industrial firewall is deployed on the basis of the existing vertical encryption device of the dispatch data network to isolate the boundary between the NCS system and the network, strengthen the security boundary access control capability, and prohibit illegal connection requests to ensure the security of data interaction in the dispatch data network.
[0032] Preferably, the auxiliary control system security protection subsystem includes:
[0033] The auxiliary control system is an industrial control security monitoring and auditing device that enables network traffic auditing and abnormal behavior alarms.
[0034] The auxiliary control system industrial control host guard is deployed on industrial control hosts, servers, interface machines and other devices to protect against malicious code and manage peripheral ports;
[0035] The auxiliary control system intrusion detection system is deployed at the network boundary of the production control area to detect anomalies and intrusion behaviors;
[0036] The auxiliary control system security operation and maintenance management system is deployed in the security management center to realize identity authentication, access control and security audit of user operation behavior in the production control area;
[0037] The auxiliary control system is a unified security management system deployed in the security management center. It enables unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0038] The auxiliary control system log auditing and analysis system is deployed in the safety management center to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events.
[0039] The auxiliary control system's network security access control system is deployed within the system security management center. It checks or restricts unauthorized devices from connecting to the internal network; it performs security checks on devices that need to access the network, and allows them to access the internal network only after the checks are passed.
[0040] The auxiliary control system industrial firewall is used to implement boundary isolation measures in the security management area. The auxiliary control system industrial firewall is deployed between various auxiliary control systems to achieve boundary isolation, strengthen security boundary access control capabilities, and prohibit illegal connection requests.
[0041] Preferably, the security protection subsystem of the electricity billing system includes:
[0042] The power billing system industrial control security monitoring and auditing equipment is deployed in the power billing system to realize network traffic auditing and abnormal behavior alarm;
[0043] The power billing system intrusion detection system is deployed at the boundary nodes of the power billing system to audit network traffic, alert on abnormal behavior, and detect network intrusion.
[0044] The electricity billing system network access control system is deployed on the electricity billing system network to check or restrict unauthorized devices from connecting to the internal network; it performs security checks on devices that need to access the network, and allows access to the internal network after the check is passed.
[0045] The electricity billing system log auditing and analysis system is deployed in the electricity billing system to collect and analyze logs from network devices, security devices, servers, and operator stations, and to monitor, statistically analyze, query, and correlate security events.
[0046] The Power Billing System Industrial Control Host Guardian is deployed on the industrial control host, server, interface machine and other equipment of the power billing system to protect against malicious code, strengthen the security of the operating system and manage the peripheral ports.
[0047] The electricity billing system operation and maintenance management system is deployed in the electricity billing system to realize user operation behavior authentication, access control and security auditing.
[0048] The unified management system for electricity billing is deployed within the electricity billing system to achieve unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0049] The industrial firewall for the electricity billing system is deployed on the basis of the existing vertical encryption device of the dispatch data network to isolate the boundary between the system and the electricity billing system, strengthen the security boundary access control capability, and prohibit illegal connection requests to ensure the data interaction security of the dispatch data network.
[0050] Preferably, the safety protection subsystem of the chemical water treatment, ash transportation, and water purification plant system includes:
[0051] The water plant system's industrial control security monitoring and auditing equipment is deployed in three systems: chemical water treatment, ash transportation, and refined water, to achieve network traffic auditing and abnormal behavior alarms.
[0052] The water plant system log auditing and analysis system is deployed in three systems: chemical water treatment, ash transportation, and refined water. It can collect and analyze logs from network devices, security devices, servers, and operator stations, and perform monitoring, statistics, high-speed querying, and correlation analysis of security events.
[0053] Water Plant System Industrial Control Host Guardian is deployed on industrial control hosts, servers, interface machines, and other equipment in three systems: chemical water treatment, ash transportation, and refined water treatment. It provides protection against malicious code, strengthens operating system security, and manages peripheral ports.
[0054] The water plant system safety operation and maintenance management system is deployed on three systems: chemical water treatment, ash export, and refined water, to realize user operation behavior identity authentication, access control, and security auditing.
[0055] The unified safety management system for the water plant is deployed across three systems: chemical water treatment, ash transportation, and refined water. It enables unified management of safety protection equipment, systems, and host safety policies, as well as unified collection and storage of safety equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0056] Preferably, the production control area security situation awareness subsystem includes:
[0057] The industrial firewall in the production control zone is deployed at the boundary of the critical business communication network within the power monitoring system area to implement logical control and protection for communication access to important business systems.
[0058] The production control area monitoring and auditing equipment and network threat perception system are deployed at key network nodes and network boundaries of the power monitoring system to achieve network traffic auditing, abnormal behavior alarms, and analysis of network attacks, especially new types of network attacks.
[0059] The production control area log auditing and analysis system is deployed in the power monitoring system to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems, and to monitor, statistically analyze, query, and correlate security events.
[0060] The Industrial Control Host Guardian for the Production Control Area is deployed on industrial control hosts, servers, interface machines, and other equipment in the power monitoring system to protect against malicious code, strengthen operating system security, and manage peripheral ports.
[0061] The production control area operation and maintenance management system is deployed on the power monitoring system to realize user operation behavior authentication, access control and security auditing;
[0062] The unified management system for the production control area is deployed on the power monitoring system to achieve unified management of safety protection equipment, systems and host security policies, unified collection and storage of safety equipment and system operation logs, improve management efficiency and reduce operation and maintenance costs;
[0063] The industrial control vulnerability scanning platform for the production control area is deployed in the power monitoring system. It selects appropriate time points to scan and control vulnerabilities in existing equipment, and scans and eliminates vulnerabilities in new equipment before it is added to the network, thereby reducing the risk of network access.
[0064] A second aspect of the present invention provides a configuration-based security protection method based on a hub power plant industrial control system, comprising:
[0065] Communication network security protection, ensuring the security of communication processes and data in industrial control systems;
[0066] Security zone boundary protection includes checking or restricting internal and external network behavior, detecting, preventing and restricting network attacks, analyzing network behavior, recording and alarming attack information, conducting security audits, and verifying the trustworthiness of boundary devices.
[0067] Secure computing environment security protection includes user authentication, regular backup and audit log backup, detection, identification and alerting for intrusions and viruses at critical nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup; and
[0068] A security management center is added, enabling system administrators to perform system management operations and audit operation records through commands or an interface, and audit administrators to perform security audit operations and audit operation records through commands or an interface. Specific management areas and security information transmission paths are set up to control security devices or security components distributed in the network. The operation status of network links, security devices, network devices, and servers is centrally monitored. Audit data from devices is summarized and analyzed, security policies, malicious code, and patch upgrades are managed, and security events in the network are detected, identified, and alerted.
[0069] A third aspect of the present invention provides an electronic device including a processor and a memory, the memory storing a plurality of instructions, the processor being configured to read the instructions and execute the method as described in the second aspect.
[0070] A fourth aspect of the present invention provides a computer-readable storage medium storing a plurality of instructions which can be read by a processor and executed as described in the second aspect.
[0071] The present invention has the following beneficial effects:
[0072] This invention, based on the current security status of power monitoring system networks and considering the relatively stable operating environment and low update frequency of industrial control systems, and in accordance with GB / T 22239-2019 "Information Security Technology - Basic Requirements for Network Security Level Protection," adopts a "whitelist" mechanism-based "white environment" solution for industrial control system network security. By monitoring industrial control network traffic and the status of industrial control hosts, collecting and analyzing industrial control network data and software operating status, a security status baseline and model under normal operating conditions of the industrial control system are established, thereby constructing a "white environment" for industrial control system network security to ensure:
[0073] (1) Only trusted devices are allowed to access the industrial control network;
[0074] (2) Only trusted messages are allowed to be transmitted on the industrial control network;
[0075] (3) Only trusted software is allowed to be executed.
[0076] Upgrading the network security protection measures for industrial control systems (ICS) enables them to monitor network security status in real time, defend against malicious attacks, and record system network behavior, thereby enhancing their security capabilities and ensuring their safe and stable operation. Simultaneously, all security protection measures meet the requirements of national and industry policies and regulations, ensuring the legal and compliant operation of the ICS. Attached Figure Description
[0077] Figure 1 This is a network structure diagram of the DCS system security protection subsystem architecture provided by the present invention.
[0078] Figure 2 The network structure diagram of the NCS system security protection subsystem provided in this invention.
[0079] Figure 3 The network structure diagram of the security protection subsystem architecture of the auxiliary control system provided by the present invention.
[0080] Figure 4 This is a network structure diagram of the security protection subsystem architecture of the electricity billing system provided by the present invention.
[0081] Figure 5 The network structure diagram of the safety protection subsystem of the chemical water treatment, ash transportation and water purification plant system provided by the present invention.
[0082] Figure 6 This is a network structure diagram of the production control area security situation awareness subsystem architecture provided by the present invention.
[0083] Figure 7 This is a schematic diagram of the electronic device structure provided by the present invention. Detailed Implementation
[0084] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0085] The method provided by this invention can be implemented in a terminal environment that may include one or more of the following components: a processor, a memory, and a display screen. The memory stores at least one instruction, which is loaded and executed by the processor to implement the method described in the following embodiments.
[0086] A processor may include one or more processing cores. The processor uses various interfaces and lines to connect various parts of the terminal, and performs various functions and processes data by running or executing instructions, programs, code sets or instruction sets stored in memory, and by calling data stored in memory.
[0087] Memory can include random access memory (RAM) or read-only memory (ROM). Memory can be used to store instructions, programs, code, code sets, or instructions.
[0088] The display screen is used to show the user interface of each application.
[0089] In addition, those skilled in the art will understand that the structure of the terminal described above does not constitute a limitation on the terminal. The terminal may include more or fewer components, or combine certain components, or have different component arrangements. For example, the terminal may also include radio frequency circuits, input units, sensors, audio circuits, power supplies, and other components, which will not be described in detail here.
[0090] This embodiment of industrial control system security construction is based on the principles of "security zoning, protection in depth, and unified monitoring":
[0091] "Security Zoning": Based on the principle of security zoning in power monitoring systems, the power monitoring system is divided into a production control zone and a management information zone. The production control zone is further divided into Security Zone I and Security Zone II. Different business systems within Security Zone I and Security Zone II are then further subdivided into separate security zones. Inter-zone and inter-zone protection measures are formulated based on the defined security zones and security zones.
[0092] "Defense in depth": Based on the results of security zone and security domain division, while formulating access control measures for regional boundary protection, it is also necessary to implement detection and protection measures for abnormal behavior, malicious code, and known and unknown attacks within the security zone and security domain; as the most important asset of the industrial control system, the industrial control host should also be hardened and protected for security.
[0093] "Unified Monitoring": Establish a unified, hierarchical monitoring system for the protection, detection, and auditing measures of each security zone and security domain. Ultimately, it will centrally display the security risks of the power monitoring system, providing a risk level for each business system within the power monitoring system, thus enabling a comprehensive understanding and control of system dynamics.
[0094] The following are high-risk items in the graded protection system that need to be addressed based on the actual on-site conditions:
[0095] 1. Strengthen access control capabilities at the boundaries of secure zones;
[0096] 2. Enhance network defense capabilities against internal and external intrusions and malicious code;
[0097] 3. Improve the ability to detect violations related to internal and external connections;
[0098] 4. Improve the system's ability to prevent host viruses;
[0099] 5. Enhance host authentication capabilities by adopting a two-factor authentication mechanism;
[0100] 6. One-click security hardening to improve the host security baseline;
[0101] 7. Close unnecessary service ports to improve intrusion prevention capabilities;
[0102] 8. Use access control policies to ensure that business configuration files are not tampered with;
[0103] 9. Improve log auditing capabilities; audit logs should be retained for at least 6 months.
[0104] 10. Strengthen the management of maintenance personnel's behavior;
[0105] 11. Establish a unified security management center to strengthen centralized control capabilities;
[0106] 12. Use technical means to assist owners in completing regular self-inspections.
[0107] This embodiment provides a configurable security protection system based on the industrial control system of a hub power plant, including:
[0108] The system includes a DCS system security protection subsystem, an NCS system security protection subsystem, an auxiliary control system security protection subsystem, an electricity billing system security protection subsystem, a chemical water treatment, ash export and water purification plant system security protection subsystem, and a production control area security situation awareness subsystem.
[0109] Each of the aforementioned subsystems includes:
[0110] The communication network security protection subsystem is used to ensure the security of communication processes and communication data in industrial control systems.
[0111] The security zone boundary security protection subsystem is used to inspect or restrict internal and external network behavior, detect, prevent and restrict network attacks, analyze network behavior, record and alarm attack information, conduct security audits and verify the trustworthiness of boundary devices.
[0112] The secure computing environment security protection subsystem is used for user authentication, regular backup of audit logs, detection, identification, and alarm for intrusion behaviors and viruses at critical nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup; and
[0113] The security management center is used by system administrators to perform system management operations and audit operation records through commands or an interface, and by audit administrators to perform security audit operations and audit operation records through commands or an interface. It allows for the setting of specific management areas and security information transmission paths to control security devices or components distributed throughout the network; centralized monitoring of the operational status of network links, security devices, network equipment, and servers; aggregation and analysis of device audit data; management of security policies, malicious code, and patch upgrades; and detection, identification, and alerting of security events in the network.
[0114] like Figure 1 As shown, in a preferred embodiment, the DCS system security protection subsystem includes:
[0115] DCS system industrial control security monitoring and auditing equipment is deployed in the DCS system of each unit to realize network traffic auditing and abnormal behavior alarm;
[0116] DCS System Industrial Control Host Guardian is deployed on industrial control hosts, servers, interface machines, and other devices in various DCS systems to protect against malicious code and manage peripheral ports.
[0117] The DCS system network threat awareness system is deployed at the network boundary of the DCS system production control area to detect anomalies, intrusion behaviors, and especially analyze new types of network attacks.
[0118] The DCS system security operation and maintenance management system is deployed within the DCS system security management area to achieve identity authentication, access control, and security auditing of user operation behaviors in the production control area.
[0119] The DCS system unified security management system is deployed within the DCS system security management area to achieve unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0120] The DCS system log auditing and analysis system is deployed in the DCS system security management area to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events.
[0121] The DCS system vulnerability scanning system is deployed in the DCS system security management area to perform vulnerability scanning and control on existing equipment, and to scan and eliminate vulnerabilities in new network access equipment in advance to reduce network access risks.
[0122] The DCS system network security access control system is deployed within the DCS system security management area to check or restrict unauthorized devices from connecting to the internal network; and to perform security checks on devices that need to access the network, allowing them to access the internal network only after the checks are passed.
[0123] The DCS system industrial firewall provides boundary isolation for the security management area, and also for the boundary isolation between units, strengthening security boundary access control capabilities and prohibiting unauthorized connection requests.
[0124] like Figure 2 As shown, in a preferred embodiment, the NCS system security protection subsystem includes:
[0125] NCS system industrial control security monitoring and auditing equipment enables network traffic auditing and abnormal behavior alarms;
[0126] NCS System Industrial Control Host Guardian is deployed on industrial control hosts, servers, interface machines, and other devices in the NCS system to protect against malicious code and manage peripheral ports.
[0127] The NCS system intrusion detection system is deployed at the network boundary of the NCS system production control area to detect anomalies and intrusion behaviors.
[0128] The NCS system security operation and maintenance management system is deployed within the NCS system security management area to realize identity authentication, access control and security auditing of user operation behavior in the production control area;
[0129] The NCS Unified Security Management System is deployed within the NCS system security management area to achieve unified management of security protection devices, systems, and host security policies, as well as unified collection and storage of security device and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0130] The NCS system log auditing and analysis system is deployed in the NCS system security management area to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events.
[0131] The NCS system network security access control system is deployed within the NCS system security management area to check or restrict unauthorized devices from connecting to the internal network; it also performs security checks on devices that need to access the network, and allows them to access the internal network only after the checks are passed.
[0132] The NCS system industrial firewall is deployed on the basis of the existing vertical encryption device of the dispatch data network to isolate the boundary between the NCS system and the network, strengthen the security boundary access control capability, and prohibit illegal connection requests to ensure the security of data interaction in the dispatch data network.
[0133] like Figure 3 As shown, in a preferred embodiment, the auxiliary control system security protection subsystem includes:
[0134] The auxiliary control system is an industrial control security monitoring and auditing device that enables network traffic auditing and abnormal behavior alarms.
[0135] The auxiliary control system industrial control host guard is deployed on industrial control hosts, servers, interface machines and other devices to protect against malicious code and manage peripheral ports;
[0136] The auxiliary control system intrusion detection system is deployed at the network boundary of the production control area to detect anomalies and intrusion behaviors;
[0137] The auxiliary control system security operation and maintenance management system is deployed in the security management center to realize identity authentication, access control and security audit of user operation behavior in the production control area;
[0138] The auxiliary control system is a unified security management system deployed in the security management center. It enables unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0139] The auxiliary control system log auditing and analysis system is deployed in the safety management center to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events.
[0140] The auxiliary control system's network security access control system is deployed within the system security management center. It checks or restricts unauthorized devices from connecting to the internal network; it performs security checks on devices that need to access the network, and allows them to access the internal network only after the checks are passed.
[0141] The auxiliary control system industrial firewall is used to implement boundary isolation measures in the security management area. The auxiliary control system industrial firewall is deployed between various auxiliary control systems to achieve boundary isolation, strengthen security boundary access control capabilities, and prohibit illegal connection requests.
[0142] like Figure 4 As shown, in a preferred embodiment, the power billing system security protection subsystem includes:
[0143] The power billing system industrial control security monitoring and auditing equipment is deployed in the power billing system to realize network traffic auditing and abnormal behavior alarm;
[0144] The power billing system intrusion detection system is deployed at the boundary nodes of the power billing system to audit network traffic, alert on abnormal behavior, and detect network intrusion.
[0145] The electricity billing system network access control system is deployed on the electricity billing system network to check or restrict unauthorized devices from connecting to the internal network; it performs security checks on devices that need to access the network, and allows access to the internal network after the check is passed.
[0146] The electricity billing system log auditing and analysis system is deployed in the electricity billing system to collect and analyze logs from network devices, security devices, servers, and operator stations, and to monitor, statistically analyze, query, and correlate security events.
[0147] The Power Billing System Industrial Control Host Guardian is deployed on the industrial control host, server, interface machine and other equipment of the power billing system to protect against malicious code, strengthen the security of the operating system and manage the peripheral ports.
[0148] The electricity billing system operation and maintenance management system is deployed in the electricity billing system to realize user operation behavior authentication, access control and security auditing.
[0149] The unified management system for electricity billing is deployed within the electricity billing system to achieve unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0150] The industrial firewall for the electricity billing system is deployed on the basis of the existing vertical encryption device of the dispatch data network to isolate the boundary between the system and the electricity billing system, strengthen the security boundary access control capability, and prohibit illegal connection requests to ensure the data interaction security of the dispatch data network.
[0151] like Figure 5 As shown, in a preferred embodiment, the safety protection subsystem of the chemical water treatment, ash transportation, and water purification plant system includes:
[0152] The water plant system's industrial control security monitoring and auditing equipment is deployed in three systems: chemical water treatment, ash transportation, and refined water, to achieve network traffic auditing and abnormal behavior alarms.
[0153] The water plant system log auditing and analysis system is deployed in three systems: chemical water treatment, ash transportation, and refined water. It can collect and analyze logs from network devices, security devices, servers, and operator stations, and perform monitoring, statistics, high-speed querying, and correlation analysis of security events.
[0154] Water Plant System Industrial Control Host Guardian is deployed on industrial control hosts, servers, interface machines, and other equipment in three systems: chemical water treatment, ash transportation, and refined water treatment. It provides protection against malicious code, strengthens operating system security, and manages peripheral ports.
[0155] The water plant system safety operation and maintenance management system is deployed on three systems: chemical water treatment, ash export, and refined water, to realize user operation behavior identity authentication, access control, and security auditing.
[0156] The unified safety management system for the water plant is deployed across three systems: chemical water treatment, ash transportation, and refined water. It enables unified management of safety protection equipment, systems, and host safety policies, as well as unified collection and storage of safety equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
[0157] like Figure 6 As shown, in a preferred embodiment, the production control area security situation awareness subsystem includes:
[0158] The industrial firewall in the production control zone is deployed at the boundary of the critical business communication network within the power monitoring system area to implement logical control and protection for communication access to important business systems.
[0159] The production control area monitoring and auditing equipment and network threat perception system are deployed at key network nodes and network boundaries of the power monitoring system to achieve network traffic auditing, abnormal behavior alarms, and analysis of network attacks, especially new types of network attacks.
[0160] The production control area log auditing and analysis system is deployed in the power monitoring system to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems, and to monitor, statistically analyze, query, and correlate security events.
[0161] The Industrial Control Host Guardian for the Production Control Area is deployed on industrial control hosts, servers, interface machines, and other equipment in the power monitoring system to protect against malicious code, strengthen operating system security, and manage peripheral ports.
[0162] The production control area operation and maintenance management system is deployed on the power monitoring system to realize user operation behavior authentication, access control and security auditing;
[0163] The unified management system for the production control area is deployed on the power monitoring system to achieve unified management of safety protection equipment, systems and host security policies, unified collection and storage of safety equipment and system operation logs, improve management efficiency and reduce operation and maintenance costs;
[0164] The industrial control vulnerability scanning platform for the production control area is deployed in the power monitoring system. It selects appropriate time points to scan and control vulnerabilities in existing equipment, and scans and eliminates vulnerabilities in new equipment before it is added to the network, thereby reducing the risk of network access.
[0165] This embodiment also provides a configuration-based security protection method based on the industrial control system of a hub power plant, including:
[0166] Communication network security protection, ensuring the security of communication processes and data in industrial control systems;
[0167] Security zone boundary protection includes checking or restricting internal and external network behavior, detecting, preventing and restricting network attacks, analyzing network behavior, recording and alarming attack information, conducting security audits, and verifying the trustworthiness of boundary devices.
[0168] Secure computing environment security protection includes user authentication, regular backup and audit log backup, detection, identification and alerting for intrusions and viruses at critical nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup; and
[0169] A security management center is added, enabling system administrators to perform system management operations and audit operation records through commands or an interface, and audit administrators to perform security audit operations and audit operation records through commands or an interface. Specific management areas and security information transmission paths are set up to control security devices or security components distributed in the network. The operation status of network links, security devices, network devices, and servers is centrally monitored. Audit data from devices is summarized and analyzed, security policies, malicious code, and patch upgrades are managed, and security events in the network are detected, identified, and alerted.
[0170] This embodiment, based on the current security status of power monitoring system networks and considering the relatively stable operating environment and low update frequency of industrial control systems, and in accordance with GB / T22239-2019 "Information Security Technology - Basic Requirements for Network Security Level Protection," adopts a "whitelist" mechanism-based "white environment" solution for industrial control system network security. By monitoring industrial control network traffic and the status of industrial control hosts, collecting and analyzing industrial control network data and software operating status, a security status baseline and model under normal operating conditions of the industrial control system are established, thereby constructing a "white environment" for industrial control system network security to ensure:
[0171] (1) Only trusted devices are allowed to access the industrial control network;
[0172] (2) Only trusted messages are allowed to be transmitted on the industrial control network;
[0173] (3) Only trusted software is allowed to be executed.
[0174] Upgrading the network security protection measures for industrial control systems (ICS) enables them to monitor network security status in real time, defend against malicious attacks, and record system network behavior, thereby enhancing their security capabilities and ensuring their safe and stable operation. Simultaneously, all security protection measures meet the requirements of national and industry policies and regulations, ensuring the legal and compliant operation of the ICS.
[0175] This embodiment also provides a memory that stores multiple instructions for implementing the method as described in the embodiment.
[0176] like Figure 7 As shown, the present invention also provides an electronic device, including a processor 301 and a memory 302 connected to the processor 301. The memory 302 stores a plurality of instructions, which can be loaded and executed by the processor to enable the processor to perform the methods as described in the embodiments.
[0177] This embodiment selects a unit with a Windows system as the host for implementation, evaluates the operational effect of the solution, and further optimizes the implementation plan for subsequent units to achieve the best implementation effect.
[0178] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if these modifications and modifications of the invention fall within the scope of the claims and their equivalents, the invention is also intended to include these modifications and modifications.
Claims
1. A configuration type security protection system based on a hub power plant industrial control system, characterized in that include: The system includes a DCS system security protection subsystem, an NCS system security protection subsystem, an auxiliary control system security protection subsystem, an electricity billing system security protection subsystem, a chemical water treatment, ash export and water purification plant system security protection subsystem, and a production control area security situation awareness subsystem. Each of the aforementioned subsystems includes: The communication network security protection subsystem is used to ensure the security of communication processes and communication data in industrial control systems. The security zone boundary security protection subsystem is used to inspect or restrict internal and external network behavior, detect, prevent and restrict network attacks, analyze network behavior, record and alarm attack information, conduct security audits and verify the trustworthiness of boundary devices. The secure computing environment security protection subsystem is used for user authentication, regular backup of audit logs, detection, identification, and alarm for intrusion behaviors and viruses at critical nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup; and The security management center is used by system administrators to perform system management operations and audit operation records through commands or an interface, and by audit administrators to perform security audit operations and audit operation records through commands or an interface. It allows for the setting of specific management areas and security information transmission paths to control security devices or components distributed throughout the network; centralized monitoring of the operational status of network links, security devices, network equipment, and servers; aggregation and analysis of device audit data; management of security policies, malicious code, and patch upgrades; and detection, identification, and alerting of security events in the network. The production control area security situation awareness subsystem includes: The industrial firewall in the production control zone is deployed at the boundary of the critical business communication network within the power monitoring system area to implement logical control and protection for communication access to important business systems. The production control area monitoring and auditing equipment and network threat perception system are deployed at key network nodes and network boundaries of the power monitoring system to audit network traffic, alarm abnormal behavior, and analyze new types of network attacks. The production control area log auditing and analysis system is deployed in the power monitoring system to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems, and to monitor, statistically analyze, query, and correlate security events. The Industrial Control Host Guardian for the Production Control Area is deployed on industrial control hosts, servers, and interface devices in the power monitoring system to protect against malicious code, strengthen operating system security, and manage peripheral ports. The production control area operation and maintenance management system is deployed on the power monitoring system to realize user operation behavior authentication, access control and security auditing; The unified management system for the production control area is deployed on the power monitoring system to achieve unified management of safety protection equipment, systems and host security policies, unified collection and storage of safety equipment and system operation logs, improve management efficiency and reduce operation and maintenance costs; The industrial control vulnerability scanning platform for the production control area is deployed in the power monitoring system. It selects appropriate time points to scan and control vulnerabilities in existing equipment, and scans and eliminates vulnerabilities in new equipment before it is added to the network, thereby reducing the risk of network access.
2. The configuration type security protection system based on the pivot power plant industrial control system according to claim 1, characterized in that The DCS system security protection subsystem includes: DCS system industrial control security monitoring and auditing equipment is deployed in the DCS system of each unit to realize network traffic auditing and abnormal behavior alarm; DCS System Industrial Control Host Guardian is deployed on the industrial control hosts, servers, and interface devices of various DCS systems to protect against malicious code and manage peripheral ports. The DCS system network threat awareness system is deployed at the network boundary of the DCS system production control area to detect anomalies, detect intrusion behaviors, and analyze new types of network attacks. The DCS system security operation and maintenance management system is deployed within the DCS system security management area to realize identity authentication, access control and security auditing of user operation behavior in the production control area. The DCS system unified security management system is deployed within the DCS system security management area to achieve unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs. The DCS system log auditing and analysis system is deployed in the DCS system security management area to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events. The DCS system vulnerability scanning system is deployed in the DCS system security management area to perform vulnerability scanning and control on existing equipment, and to scan and eliminate vulnerabilities in new network access equipment in advance to reduce network access risks. The DCS system network security access control system is deployed within the DCS system security management area to check or restrict unauthorized devices from connecting to the internal network; and to perform security checks on devices that need to access the network, allowing them to access the internal network only after the checks are passed. The DCS system industrial firewall provides boundary isolation for the security management area, and also for the boundary isolation between units, strengthening security boundary access control capabilities and prohibiting unauthorized connection requests.
3. The configuration type security protection system based on the pivot power plant industrial control system according to claim 1, characterized in that The NCS system security protection subsystem includes: NCS system industrial control security monitoring and auditing equipment enables network traffic auditing and abnormal behavior alarms; NCS System Industrial Control Host Guardian is deployed on industrial control hosts, servers, and interface devices in the NCS system to protect against malicious code and manage peripheral ports. The NCS system intrusion detection system is deployed at the network boundary of the NCS system production control area to detect anomalies and intrusion behaviors. The NCS system security operation and maintenance management system is deployed within the NCS system security management area to realize identity authentication, access control and security auditing of user operation behavior in the production control area. The NCS Unified Security Management System is deployed within the NCS system security management area to achieve unified management of security protection devices, systems, and host security policies, as well as unified collection and storage of security device and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs. The NCS system log auditing and analysis system is deployed in the NCS system security management area to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events. The NCS system network security access control system is deployed within the NCS system security management area to check or restrict unauthorized devices from connecting to the internal network; it also performs security checks on devices that need to access the network, and allows them to access the internal network only after the checks are passed. The NCS system industrial firewall is deployed on the basis of the existing vertical encryption device of the dispatch data network to isolate the boundary between the NCS system and the network, strengthen the security boundary access control capability, and prohibit illegal connection requests to ensure the security of data interaction in the dispatch data network.
4. The configuration type security protection system based on the pivot power plant industrial control system according to claim 1, characterized in that The auxiliary control system security protection subsystem includes: The auxiliary control system is an industrial control security monitoring and auditing device that enables network traffic auditing and abnormal behavior alarms. The auxiliary control system industrial control host guard is deployed on industrial control hosts, servers, and interface devices to protect against malicious code and manage peripheral ports; The auxiliary control system intrusion detection system is deployed at the network boundary of the production control area to detect anomalies and intrusion behaviors; The auxiliary control system security operation and maintenance management system is deployed in the security management center to realize identity authentication, access control and security audit of user operation behavior in the production control area; The auxiliary control system is a unified security management system deployed in the security management center. It enables unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs. The auxiliary control system log auditing and analysis system is deployed in the safety management center to collect and analyze logs from network devices, security devices, servers, operator stations, and database systems in the production control area, and to monitor, statistically analyze, query, and correlate security events. The auxiliary control system's network security access control system is deployed within the system security management center. It checks or restricts unauthorized devices from connecting to the internal network; it performs security checks on devices that need to access the network, and allows them to access the internal network only after the checks are passed. The auxiliary control system industrial firewall is used to implement boundary isolation measures in the security management area. The auxiliary control system industrial firewall is deployed between various auxiliary control systems to achieve boundary isolation, strengthen security boundary access control capabilities, and prohibit illegal connection requests.
5. The configuration security protection system based on the pivot power plant industrial control system according to claim 1, characterized in that The security protection subsystem of the electricity billing system includes: The power billing system industrial control security monitoring and auditing equipment is deployed in the power billing system to realize network traffic auditing and abnormal behavior alarm; The power billing system intrusion detection system is deployed at the boundary nodes of the power billing system to audit network traffic, alarm for abnormal behavior, and detect network intrusion. The electricity billing system network access control system is deployed on the network of the electricity billing system to check or restrict unauthorized devices from connecting to the internal network; it also performs security checks on devices that need to access the network, and allows them to access the internal network after the checks are passed. The electricity billing system log auditing and analysis system is deployed in the electricity billing system to collect and analyze logs from network devices, security devices, servers, and operator stations, and to monitor, statistically analyze, query, and correlate security events. The Power Billing System Industrial Control Host Guardian is deployed on the industrial control host, server, and interface equipment of the power billing system to protect against malicious code, strengthen the security of the operating system, and manage the peripheral ports. The electricity billing system operation and maintenance management system is deployed in the electricity billing system to realize user operation behavior authentication, access control and security auditing. The unified management system for electricity billing is deployed within the electricity billing system to achieve unified management of security protection equipment, systems, and host security policies, as well as unified collection and storage of security equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs. The industrial firewall for the electricity billing system is deployed on the basis of the existing vertical encryption device of the dispatch data network to isolate the boundary between the system and the electricity billing system, strengthen the security boundary access control capability, and prohibit illegal connection requests to ensure the data interaction security of the dispatch data network.
6. The configuration security protection system based on the pivot power plant industrial control system according to claim 1, characterized in that The safety protection subsystem of the chemical water treatment, ash transportation, and water purification plant system includes: The water plant system's industrial control security monitoring and auditing equipment is deployed in three systems: chemical water treatment, ash transportation, and refined water, to achieve network traffic auditing and abnormal behavior alarms. The water plant system log auditing and analysis system is deployed in three systems: chemical water treatment, ash transportation, and refined water. It can collect and analyze logs from network devices, security devices, servers, and operator stations, and perform monitoring, statistics, high-speed querying, and correlation analysis of security events. Water Plant System Industrial Control Host Guardian is deployed on the industrial control hosts, servers, and interface equipment of the three systems of chemical water treatment, external ash transportation, and refined water to achieve protection against malicious code, harden the operating system security, and manage the peripheral ports. The water plant system safety operation and maintenance management system is deployed on three systems: chemical water treatment, ash external transmission, and refined water, to realize user operation behavior identity authentication, access control, and security auditing. The unified safety management system for the water plant is deployed across three systems: chemical water treatment, ash transportation, and refined water. It enables unified management of safety protection equipment, systems, and host safety policies, as well as unified collection and storage of safety equipment and system operation logs, thereby improving management efficiency and reducing operation and maintenance costs.
7. A protection method based on the configuration-based security protection system of the power plant industrial control system according to any one of claims 1 to 6, the method comprising: Communication network security protection, ensuring the security of communication processes and data in industrial control systems; Security zone boundary protection includes checking or restricting internal and external network behavior, detecting, preventing and restricting network attacks, analyzing network behavior, recording and alarming attack information, conducting security audits, and verifying the trustworthiness of boundary devices. Secure computing environment security protection includes user identity authentication, regular backup of audit logs, detection, identification and alarm for intrusion behavior and viruses at important nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup. as well as A security management center is added, enabling system administrators to perform system management operations and audit operation records through commands or an interface, and audit administrators to perform security audit operations and audit operation records through commands or an interface; specific management areas and security information transmission paths are set up to control security devices or security components distributed in the network; and the operational status of network links, security devices, network devices, and servers is centrally monitored. It summarizes and analyzes audit data from devices, manages security policies, malicious code and patch upgrades, and detects, identifies and alerts on security incidents in the network.
8. An electronic device, comprising: It includes a processor and a memory, the memory storing multiple instructions, and the processor for reading the instructions and executing the method as described in claim 7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions, which can be read by a processor and executed as described in claim 7.
Citation Information
Patent Citations
Distributive management system of information network security for power enterprises
CN103227797A