An Industrial Control System Security Protection Method, Device, Equipment and Medium

By constructing the state transfer model and probability matrix of the industrial control system, the target nodes whose average failure time is less than the fault repair time are selected, and the nodes are replaced to operate within a specific time period, the shortcomings of the existing industrial control system safety protection methods are solved and the system safety and reliability are improved.

CN114547600BActive Publication Date: 2025-07-04EVERSEC BEIJING TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210157430.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-21
Publication Date
2025-07-04
Estimated Expiration
2042-02-21

AI Technical Summary

Technical Problem

The existing safety protection methods of industrial control systems cannot detect and prevent intrusion behavior in real time and accurately, resulting in the inability to effectively protect the safety of industrial control systems.

Method used

By constructing the state transfer model of the industrial control system and the state transfer probability matrix space, the average failure time of each working node switches from the current state to the stop service state is determined, and the target node with an average failure time is selected for filtering out the target node whose average failure time is less than the fault repair time, and between the fault time point, the target node is selected from the alternative nodes to replace the target node to continue running.

Benefits of technology

It improves the operating time of the industrial control system failure, effectively protects the industrial control system, and reduces losses caused by the failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114547600B_ABST
    Figure CN114547600B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a method, device, equipment and medium for industrial control system security protection. The method includes: determining the average time to failure for each working node in the industrial control system to switch from the current node state to the stop service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space; screening out target nodes with an average time to failure less than the fault repair time, and determining the corresponding fault time points and fault repair time points for the target nodes; within the interrupt service time period determined by the fault time points and the fault repair time points, selecting at least one target alternative node from the alternative node set to replace the target node and continue running. The technical solution of the embodiment of the present invention can improve the fault operation time of the industrial control system, thereby effectively protecting the industrial control system from security threats and reducing the losses caused by faults in the industrial control system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of computer technology, and in particular, to a method, device, equipment and medium for industrial control system security protection. Background Art

[0002] Industrial Control Systems (ICS) is abbreviated as industrial control system, which is the nervous system of today's industrial critical infrastructure. The industrial control system is a complex system, and the networking and forms of industrial control systems in different industries will vary greatly. Generally, a simple industrial control system consists of a main control unit and a Programmable Logic Controller (PLC). More complex ones rise to a Computer Control System (CCS) or a Distributed Control System (DCS), as well as a Data Acquisition and Monitoring Control System (SCADA) based on computer components. The design goal of the industrial control system is to realize the automation of the production process and maximize the benefits, and the system can meet the production process with a stable attitude and high reliability requirements.

[0003] With the development of computer technology, communication technology and control technology, traditional industrial control systems that use closed networks and have no external interconnection and interoperability are gradually moving towards openness and interconnection, undergoing an unprecedented transformation. They widely use TCP / IP (Transmission Control Protocol / Internet Protocol) networks as the basic communication infrastructure, including various wireless communication networks such as GPRS (General Packet Radio Service), and begin to develop in the direction of networking. Therefore, when the industrial control system transmits data to the outside world, there is a risk of being attacked or invaded.

[0004] Existing industrial control system security protection methods usually use software programs to detect and block intrusion behaviors. However, intrusion behaviors and weaknesses of industrial control systems are unpredictable and random. Therefore, existing industrial control system security protection methods cannot effectively protect the industrial control system because they cannot detect and block intrusion behaviors in real time and accurately. Summary of the Invention

[0005] Embodiments of the present invention provide a method, device, equipment and medium for industrial control system security protection, which can increase the fault operation time of the industrial control system, thereby effectively protecting the industrial control system and reducing the losses caused by faults in the industrial control system.

[0006] According to one aspect of the present invention, there is provided a method for industrial control system security protection, including:

[0007] According to the industrial control system state transition model and the industrial control system state transition probability matrix space, determine the mean time to failure for each working node in the industrial control system to switch from the current node state to the stopped service state;

[0008] Filter out the target nodes whose mean time to failure is less than the fault repair time, and based on the mean time to failure and the fault repair time, determine the corresponding fault time points and fault repair time points for the target nodes;

[0009] During the interruption service time period determined by the fault time points and the fault repair time points, select at least one target alternative node from the alternative node set to replace the target node and continue running.

[0010] According to another aspect of the present invention, there is provided an industrial control system security protection device, characterized by comprising:

[0011] A mean time to failure determination module, configured to determine the mean time to failure for each working node in the industrial control system to switch from the current node state to the stopped service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space;

[0012] A target node screening module, configured to filter out the target nodes whose mean time to failure is less than the fault repair time, and based on the mean time to failure and the fault repair time, determine the corresponding fault time points and fault repair time points for the target nodes;

[0013] A target alternative node replacement module, configured to select at least one target alternative node from the alternative node set to replace the target node and continue running during the interruption service time period determined by the fault time points and the fault repair time points.

[0014] According to another aspect of the present invention, there is provided an electronic device, the electronic device comprising:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the industrial control system security protection method described in any embodiment of the present invention.

[0018] According to another aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium storing computer instructions for causing a processor to execute the industrial control system security protection method described in any embodiment of the present invention when executed.

[0019] The technical solution of the embodiment of the present invention determines the mean time to failure (MTTF) for each working node in the industrial control system to switch from the current node state to the stopped service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space, and filters out the target nodes with an MTTF less than the mean time to repair (MTTR). Then, based on the MTTF and MTTR, the corresponding failure time point and repair time point for the target nodes are determined. Furthermore, within the interruption service time period determined by the failure time point and the repair time point, at least one target alternative node is selected from the set of alternative nodes to replace the target node and continue running, solving the problem that the existing industrial control system security protection method cannot effectively protect the industrial control system because it cannot detect and prevent intrusion behaviors in real time and accurately. It can increase the fault-free running time of the industrial control system, thus effectively protecting the industrial control system and reducing the losses caused by faults in the industrial control system.

[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0022] Figure 1 is a flowchart of a method for protecting the security of an industrial control system provided in Embodiment 1 of the present invention;

[0023] Figure 2 is a schematic structural diagram of a distributed industrial control system provided in Embodiment 1 of the present invention;

[0024] Figure 3 is a schematic structural diagram of an industrial control system state transition model provided in Embodiment 1 of the present invention;

[0025] Figure 4 is a flowchart of a method for protecting the security of an industrial control system provided in Embodiment 2 of the present invention;

[0026] Figure 5 is a schematic diagram of a subnet switching model provided in Embodiment 2 of the present invention;

[0027] Figure 6It is a schematic diagram of an industrial control system security protection device provided in Embodiment 3 of the present invention;

[0028] Figure 7 It is a schematic structural diagram of an electronic device for implementing the industrial control system security protection method of the embodiments of the present invention. Detailed implementation manners

[0029] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0030] It should be noted that the terms "target" and the like in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0031] Embodiment 1

[0032] Figure 1 It is a flowchart of an industrial control system security protection method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of improving the fault operation time of the industrial control system. This method can be executed by an industrial control system security protection device, which can be implemented in software and / or hardware, and generally can be directly integrated in the electronic device executing this method. This electronic device can be a terminal device or a server device. The embodiments of the present invention do not limit the type of the electronic device executing the industrial control system security protection method. Specifically, as Figure 1 shown, the industrial control system security protection method can specifically include the following steps:

[0033] S110. Determine the average time to failure for each working node in the industrial control system to switch from the current node state to the stopped service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space.

[0034] Among them, the industrial control system state transition model can be a model that characterizes different working states of working nodes in the industrial control system and the transition relationships between different working states. The industrial control system state transition probability matrix space can be a matrix space formed by transition probability matrices between different working states of each working node in the industrial control system. Exemplarily, assuming that the working states of the working node M in the industrial control system include state A and state B, the transition probability between different working states of the working node M can be the probability of transitioning from state A to state B. The current node state can be the current state of the working node. It can be understood that the current node states of different working nodes can be different. Exemplarily, the current node state of the working node M can be state A; the current node state of the working node N can be state B. The stop service state can be a state where the working node cannot continue to run and stops service. The mean time to failure can be the time elapsed from normal operation to non-operation of the working node, which can be used to characterize the ability of the working node to handle faults. It can be understood that the mean time to failure is a duration. The larger the mean time to failure, the longer the interval from the fault of the working node to the stop of operation, that is, the stronger the ability of the working node to handle faults.

[0035] In an embodiment of the present invention, when performing security protection on the industrial control system, the mean time to failure for each working node in the industrial control system to switch from the current node state to the stop service state can be determined according to the industrial control system state transition model and the industrial control system state transition probability matrix space, so as to screen out target nodes with a mean time to failure less than the fault repair time. It can be understood that when a node is invaded and attacked, the number of state switches is limited and cannot switch infinitely. It may finally switch to the normal state and continue to run, or it may switch to the stop service state.

[0036] Optionally, the industrial control system may include a distributed industrial control system. A distributed industrial control system is a specially designed system that is often used in industrial control processes for complex, large-scale, or geographically distributed applications, which can improve reliability, productivity, and production quality while minimizing production costs. Figure 2 is a schematic diagram of the architecture of the distributed industrial control system provided in Embodiment 1 of the present invention. In a specific example, as Figure 2 shown, the distributed industrial control system may include an industrial control center, as well as at least one actuator for control and a wireless communication network, and at least one controller and at least one sensor of the actuator, and are connected through a wireless network. It can be understood that the communication network may include multiple subnets, and each subnet may include multiple working nodes. Nodes in the communication network may cause failures of the distributed industrial control system when under external attacks, so security protection needs to be performed on the industrial control system.

[0037] Optionally, before determining the mean time to failure for each working node in the industrial control system to switch from the current node state to the stopped service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space, the method further includes: collecting historical operation status data of each node in the industrial control system; generating an industrial control system state transition model according to the historical operation status data, and establishing an industrial control system state transition probability matrix corresponding to each node respectively, so as to form an industrial control system state transition probability matrix space.

[0038] Among them, the historical operation status data may be the status data of the nodes in the industrial control system during the historical operation process. The industrial control system state transition probability matrix may be a probability matrix formed by the transition probabilities between different working states of the nodes.

[0039] Specifically, when performing security protection on the industrial control system, the historical operation status data of each node in the industrial control system may be collected to generate an industrial control system state transition model according to the historical operation status data, and an industrial control system state transition probability matrix corresponding to each node respectively may be established to form an industrial control system state transition probability matrix space, so as to determine the mean time to failure for each working node in the industrial control system to switch from the current node state to the stopped service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space.

[0040] It can be understood that the industrial control system state transition model may include a node state set and the transition relationships between different node states in the node state set. Optionally, the node states in the node state set may include a normal state, a vulnerable state, an attacked state, a waiting for improvement state, a trigger state, a stopped service state, a reduced service state, and an unknown damage state.

[0041] Figure 3 is a schematic structural diagram of the industrial control system state transition model provided in the first embodiment of the present invention. In a specific example, such as Figure 3As shown in the figure, in a distributed industrial control system, if the j-th node of the i-th subnet of the distributed industrial control system is in the N state (Normal State), the node can operate normally, where i ∈ [1, I], I represents the number of subnets, j ∈ [1, J], and J represents the number of nodes. Both I and J are positive integers greater than 1. When the distributed industrial control system detects or discovers a vulnerability, the node enters the F state (Fragile State). If the node automatically repairs itself, it returns to the N state; if the node is successfully invaded by an attacker using the vulnerability, the node enters the BA state (Being Attacked State); if the node avoids damage through a defense strategy, at this time the node needs to be maintained and repaired by an operator and enters the WI state (Waiting for Improving State); if the vulnerability of the node is improved or repaired by the administrator, the node continues to enter the N state; if the node is in the BA state and cannot avoid the damage or fails to shield the damage caused by the intruder, the intrusion tolerance mechanism will be triggered and the node enters the T state (Trigger State); when the node is in the T state, the intrusion tolerance mechanism will evaluate the current damage situation. If it is determined that the node is severely damaged or completely out of control and cannot continue to operate, the node enters the SS state (Stop the Service State); if the node can still continue to operate but needs to reduce some performance or service capabilities, the node enters the RS state (reduce the service state); after the node is in the SS state or RS state and is maintained and improved by the administrator, it enters the N state; if the node is in the BA state and fails to avoid the damage and also fails to trigger the intrusion tolerance mechanism, it enters the UD state (unknowndamage state), and at this time the node needs to be improved or repaired by the administrator and will re-enter the N state.

[0042] Specifically, the intrusion tolerance mechanism can be the ability to still timely judge and complete its key tasks when the distributed industrial control system suffers a successful malicious attack, and can provide all or degraded services, that is, the intrusion tolerance technology. The intrusion tolerance technology does not trust any single node in the network and will not cause the entire distributed industrial control system to crash because a certain node is compromised. The system decentralizes power to multiple nodes and abandons a node when it detects that the node is occupied, ensuring that the system will not damage the availability and confidentiality of the system due to a single node and scenario.

[0043] Another understandable point is that each matrix element in the state transition probability matrix of the industrial control system can be used to describe the transition probability of switching from one node state in the node state set to another node state. Optionally, the state transition probability matrix of the industrial control system can be constructed based on a discrete-time Markov model. The Markov model is a probability statistical model that can be used to model various complex dynamic systems. The state transition probability matrix of the industrial control system can be used to describe the state transformation relationship of the industrial control system providing services externally. By modeling, the operating state of the system can be further quantified, and then the performance indicators of the system can be efficiently analyzed. In a specific example, the horizontal direction of the state transition probability matrix of the industrial control system can represent the initial state of the node, and the vertical direction of the state transition probability matrix of the industrial control system can represent the state after the node switches from the initial state. The state transition probability matrix of the industrial control system can be specifically represented in the following form:

[0044]

[0045] Among them, represents the state transition probability matrix of the industrial control system of the j-th node in the i-th subnet, represents the probability that the node transfers from state N to state N in one step, that is, the probability of normal operation; represents the probability that the node transfers from state N to state F in one step, that is, the probability that the intrusion vulnerability of the node is discovered; represents the probability that the node transfers from state F to state N in one step, that is, the probability that the node can automatically recover; represents the probability that the node transfers from state F to state BA in one step, that is, the probability that the attacker successfully invades using the vulnerability; represents the probability that the node transfers from state BA to state WI in one step, that is, the probability that the node shields the intrusion but requires the administrator to repair; represents the probability that the node transfers from state WI to state N in one step, that is, the probability that the node operates normally after being improved or repaired by the administrator; represents the probability that the node transfers from state BA to state T in one step, that is, the probability that the node cannot avoid damage or the damage caused by failing to shield the intruder, triggering the intrusion tolerance mechanism; represents the probability that the node transfers from state T to state SS in one step, that is, the probability that the node is severely damaged or completely out of control and cannot continue to operate; represents the probability that the node transfers from state T to state RS in one step, that is, the probability that the node can still continue to operate, but needs to reduce part of its performance or service capacity; represents the probability that the node transfers from state RS to state WI in one step, that is, the probability that the node provides degraded services and needs to wait for the administrator to improve and repair; It represents the probability that the node transfers from the SS state to the WI state at one time, that is, the probability that the node is completely out of control or cannot run and needs to wait for the administrator to improve and repair it; It represents the probability that the node transfers from the BA state to the UD state at one time, that is, when the node is in the BA state, the probability that it fails to avoid damage and does not trigger the tolerance mechanism; It represents the probability that the node transfers from the UD state to the N state at one time, that is, the probability that the node can run normally after being repaired by the administrator from the UD state; the transfer probability by other means is recorded as 0, that is, there is no other way of transfer for the node. It can be understood that a one-time transfer means starting from this state and only going through one transfer, without superposition times. The value range of all probabilities is from 0 to 1.

[0046] S120. Screen out the target nodes with the mean time to failure less than the time to repair the failure, and determine the failure time point and the time to repair the failure corresponding to the target nodes according to the mean time to failure and the time to repair the failure.

[0047] Among them, the time to repair the failure can be the time required for the working node to complete the failure repair from the start of the failure. Optionally, the time to repair the failure can be the maximum time required for the working node to complete the failure repair from the start of the failure. The target node can be a node selected from the working nodes that satisfies the mean time to failure less than the time to repair the failure. The failure time point can be the time point when the working node cannot run normally, that is, the time point at the end of the mean time to failure. The time to repair the failure point can be the time point when the target node completes the failure repair, that is, the time point at the end of the time to repair the failure.

[0048] In the embodiment of the present invention, after determining the mean time to failure for each working node in the industrial control system to switch from the current node state to the stop service state, the target nodes with the mean time to failure less than the time to repair the failure can be further screened out, and the failure time point and the time to repair the failure corresponding to the target nodes are determined according to the mean time to failure and the time to repair the failure.

[0049] It can be understood that if the mean time to failure of the working node is less than the time to repair the failure, it means that the working node stops service before completing the failure repair, then the working node cannot continue to work, which may lead to the failure of the industrial control system. Therefore, in the embodiment of the present invention, the target nodes with the mean time to failure less than the time to repair the failure are screened out, and the failure time point and the time to repair the failure corresponding to the target nodes are determined according to the mean time to failure and the time to repair the failure, so as to select at least one target alternative node from the alternative node set to replace the target node and continue to run during the interruption service time period determined by the failure time point and the time to repair the failure point.

[0050] S130. During the interruption service time period determined by the failure time point and the failure recovery time point, select at least one target alternative node from the alternative node set to replace the target node and continue to run.

[0051] Among them, the interruption service time period can be the time period from when the target node fails and cannot run until the failure is repaired. The alternative node set can be a set of non-working nodes used for standby in the industrial control system. The target alternative node can be a target node in the alternative node set and can be used to replace the target node and continue to run.

[0052] In the embodiment of the present invention, after screening out the target nodes with an average failure time less than the failure recovery time, and determining the failure time point and the failure recovery time point corresponding to the target nodes according to the average failure time and the failure recovery time, it is further possible to select at least one target alternative node from the alternative node set to replace the target node and continue to run during the interruption service time period determined by the failure time point and the failure recovery time point until the current system time reaches the failure recovery time point, that is, the target node is repaired, and switch the target alternative node back to the target node, and the target node continues to run to avoid system downtime or system out-of-control caused by node failures in the industrial control system, thereby realizing the security protection of the industrial control system.

[0053] The technical solution of this embodiment determines the average failure time for each working node in the industrial control system to switch from the current node state to the stop service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space, and screens out the target nodes with an average failure time less than the failure recovery time. Then, according to the average failure time and the failure recovery time, the failure time point and the failure recovery time point corresponding to the target nodes are determined. Furthermore, during the interruption service time period determined by the failure time point and the failure recovery time point, at least one target alternative node is selected from the alternative node set to replace the target node and continue to run, solving the problem that the existing industrial control system security protection method cannot effectively protect the industrial control system because it cannot detect and prevent intrusion behaviors in real time and accurately. It can increase the failure operation time of the industrial control system, thereby effectively protecting the industrial control system and reducing the losses caused by failures in the industrial control system.

[0054] Embodiment 2

[0055] Figure 4It is a flowchart of a method for industrial control system security protection provided in the second embodiment of the present invention. This embodiment further refines the above technical solutions, and gives various specific optional implementation manners for determining the average time to failure experienced by each working node in the industrial control system to switch from the current node state to the stop service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space, and for selecting at least one target alternative node from the alternative node set to replace the target node to continue running during the interruption service period determined by the failure time point and the failure repair time point. The technical solutions in this embodiment can be combined with the various optional solutions in one or more of the above embodiments. As Figure 4 shown, the method may include the following steps:

[0056] S410. Obtain the current processing node in the industrial control system, and determine the current operating state data of the current processing node.

[0057] Among them, the current processing node may be the working node currently being processed in the industrial control system. Exemplarily, if the industrial control system includes working node A and working node B, and the average time to failure of working node A is currently being determined, then working node A can be determined as the current processing node. The current operating state data may be data that can characterize the current operating state of the current processing node.

[0058] In the embodiment of the present invention, the current processing node is obtained in the industrial control system, and the current operating state data of the current processing node is determined to determine the current node state corresponding to the current processing node according to the current operating state data. Specifically, obtaining the current processing node in the industrial control system may be to obtain any one of the working nodes in the industrial control system as the current processing node. It should be noted that the embodiment of the present invention does not limit the specific implementation manner of determining the current operating state data of the current processing node, as long as the determination of the current operating state data of the current processing node can be achieved.

[0059] S420. Determine the current node state corresponding to the current processing node according to the current operating state data.

[0060] Among them, the current node state may be the current operating state of the current processing node. For example, it may be a normal state, a vulnerable state, an attacked state, or a triggered state. The embodiment of the present invention does not limit this. It can be understood that the current processing node is any normally operating node among the working nodes. Therefore, the current node state of the current processing node does not include the waiting improvement state, the stop service state, the reduced service state, and the unknown damage state in the node state set.

[0061] In an embodiment of the present invention, after obtaining a current processing node in an industrial control system and determining current operation state data of the current processing node, a current node state corresponding to the current processing node may be further determined according to the current operation state data.

[0062] S430. Obtain at least one target node state in the industrial control system state transition model according to the current node state.

[0063] Among them, the target node state may be a node state corresponding to the current node state. Exemplarily, if the current node state is a normal state, the target node state may be a normal state, a vulnerable state, an attacked state, or a triggered state. If the current node state is a vulnerable state, the target node state may be a vulnerable state, an attacked state, or a triggered state. If the current node state is an attacked state, the target node state may be an attacked state or a triggered state. If the current node state is a triggered state, the target node state may be a triggered state.

[0064] In an embodiment of the present invention, after determining a current node state corresponding to the current processing node according to the current operation state data, at least one target node state may be further obtained in the industrial control system state transition model according to the current node state. Specifically, obtaining at least one target node state in the industrial control system state transition model according to the current node state may be obtaining at least one target node state that satisfies different node state transition rules in the industrial control system state transition model according to the current node state.

[0065] S440. Obtain a target industrial control system state transition probability matrix corresponding to the current processing node in the industrial control system state transition probability matrix space.

[0066] Among them, the target industrial control system state transition probability matrix may be a matrix that can represent the transition probability of the current processing node between different working states. It can be understood that in the industrial control system state transition probability matrix space, industrial control system state transition probability matrices corresponding to each node may be included.

[0067] In an embodiment of the present invention, after obtaining at least one target node state in the industrial control system state transition model according to the current node state, a target industrial control system state transition probability matrix corresponding to the current processing node may be further obtained in the industrial control system state transition probability matrix space.

[0068] S450. Calculate the expected value of the number of times the current processing node passes through each of the target node states when switching from the current node state to the stop service state according to the target industrial control system state transition probability matrix.

[0069] Among them, the expected number of times can be the expected number of times that the current processing node passes through each target node state during the process of switching from the current node state to the stopped service state when working.

[0070] In the embodiment of the present invention, after obtaining the target industrial control system state transition probability matrix corresponding to the current processing node, the expected number of times that the current processing node passes through each target node state when switching from the current node state to the stopped service state can be further calculated according to the target industrial control system state transition probability matrix.

[0071] Optionally, calculating the expected number of times that the current processing node passes through each target node state when switching from the current node state to the stopped service state according to the target industrial control system state transition probability matrix includes: calculating the expected number of times that the current processing node passes through each target node state when switching from the current node state to the stopped service state based on the following formula according to the target industrial control system state transition probability matrix:

[0072]

[0073]

[0074]

[0075]

[0076] Among them, represents the expected number of times that the j-th node of the i-th subnet passes through the normal state when switching from the current node state to the stopped service state; represents the expected number of times that the j-th node of the i-th subnet passes through the vulnerable state when switching from the current node state to the stopped service state; represents the expected number of times that the j-th node of the i-th subnet passes through the attacked state when switching from the current node state to the stopped service state; represents the expected number of times that the j-th node of the i-th subnet passes through the triggered state when switching from the current node state to the stopped service state; represents the probability that the j-th node of the i-th subnet transfers from the normal state to the vulnerable state; represents the probability that the j-th node of the i-th subnet transfers from the vulnerable state to the attacked state; represents the probability that the j-th node of the i-th subnet transfers from the attacked state to the triggered state.

[0077] S460. Calculate the state duration of the current processing node in each of the target node states, and calculate the mean time to failure corresponding to the current processing node according to the expected number of times and the state duration corresponding to the current processing node.

[0078] Among them, the state duration can be the duration that the current processing node continuously works in the target node state when working.

[0079] In the embodiment of the present invention, after calculating the expected value of the number of times that the current processing node switches from the current node state to the stop service state through each target node state according to the target industrial control system state transition probability matrix, the state duration of the current processing node in each target node state can be further calculated, so as to calculate the mean time to failure corresponding to the current processing node according to the expected value of the number of times corresponding to the current processing node and the state duration.

[0080] Optionally, calculating the mean time to failure corresponding to the current processing node according to the expected value of the number of times corresponding to the current processing node and the state duration includes: calculating the mean time to failure corresponding to the current processing node based on the following formula according to the expected value of the number of times corresponding to the current processing node and the state duration:

[0081]

[0082] where l represents the target node state, n represents the number of target node states, represents the mean time to failure of the j-th node in the i-th subnet; represents the expected value of the number of times that the j-th node in the i-th subnet switches from the current node state to the stop service state through the target node state; represents the state duration of the j-th node in the i-th subnet in the target node state.

[0083] Exemplarily, if the current node state of the current processing node is the normal state, and the target node states of the current processing node include the normal state, the vulnerable state, the attacked state, and the triggered state, then the mean time to failure of the current processing node is ATOSF = C N T N +C F T F +C BA T BA +C T T T . If the current node state of the current processing node is the vulnerable state, and the target node states of the current processing node include the vulnerable state, the attacked state, and the triggered state, then the mean time to failure of the current processing node is ATOSF = C F T F +C BA T BA +C T T TIf the current node state of the current processing node is the attacked state, and the target node states of the current processing node include the attacked state and the triggered state, the average time to failure of the current processing node is ATOSF = C BA T BA +C T T T If the current node state of the current processing node is the triggered state, and the target node states of the current processing node include the triggered state, the average time to failure of the current processing node is ATOSF = C T T T 。

[0084] S470. Screen out target nodes whose average time to failure is less than the time to repair the failure, and determine the failure time point and the time to repair the failure corresponding to the target node according to the average time to failure and the time to repair the failure.

[0085] S480. During the interrupt service time period determined by the failure time point and the time to repair the failure, select at least one target alternative node from the alternative node set to replace the target node and continue to run.

[0086] Optionally, during the interrupt service time period determined by the failure time point and the time to repair the failure, selecting at least one target alternative node from the alternative node set to replace the target node and continue to run includes: when the current system time point reaches the failure time point, selecting a target alternative node from the alternative node set to continue to run, and determining the average time to failure for the target alternative node to switch from the normal state to the stop service state; determining the failure time point corresponding to the target alternative node according to the average time to failure of the target alternative node; when the failure time point corresponding to the target alternative node does not reach the time to repair the failure, return to execute when the current system time point reaches the failure time point, select a target alternative node from the alternative node set to continue to run, until the failure time point corresponding to the target alternative node reaches the time to repair the failure.

[0087] Wherein, the current system time point may be the current time point of the system.

[0088] Specifically, after determining the failure time point and the failure recovery time point corresponding to the target node according to the mean time between failures and the failure recovery time, when the current system time point reaches the failure time point, a target alternative node can be further selected from the set of alternative nodes to continue running, and the mean time between failures for the target alternative node to switch from the normal state to the stopped service state can be determined, so as to determine the failure time point corresponding to the target alternative node according to the mean time between failures corresponding to the target alternative node. Thus, when the failure time point corresponding to the target alternative node does not reach the failure recovery time point, return to execute the operation of selecting a target alternative node from the set of alternative nodes to continue running when the current system time point reaches the failure time point, until the failure time point corresponding to the target alternative node reaches the failure recovery time point.

[0089] It can be understood that when the current system time point reaches the failure time point, it can be the time point when the current system time point reaches the time point when the target node cannot operate normally, that is, the target node cannot continue to run at the current time.

[0090] Another thing that can be understood is that after selecting a target alternative node from the set of alternative nodes to continue running, the target alternative node becomes a working node, that is, the target alternative node is no longer included in the set of alternative nodes. That is, when returning to execute the operation of selecting a target alternative node from the set of alternative nodes to continue running, the target alternative node selected again is different from the target alternative node selected last time. The failure time point corresponding to the target alternative node does not reach the failure recovery time point, indicating that when the target alternative node stops running, the failure repair of the target node is not completed. Then, when the current system time point reaches the failure time point corresponding to the target alternative node, a target alternative node needs to be selected from the set of alternative nodes again to continue running.

[0091] In a specific example, Figure 5 is a schematic diagram of a subnet switching model provided in the second embodiment of the present invention. As Figure 5 shown, after the distributed industrial control system is attacked by intrusion, determine the current node state and the target node state of the current processing node, calculate the expected value of the number of times and the state duration corresponding to the target node state, and determine the mean time between failures of the current processing node according to the expected value of the number of times and the state duration corresponding to the target node state.

[0092] When the mean time between failures of the current processing node is less than the failure recovery time, switch the current processing node to an alternative node at the end of the mean time between failures of the current processing node to continue executing the tasks of the industrial control system. If the failure recovery time is not reached at the end of the mean time between failures of the alternative node, continue to switch to the next alternative node to continue running until the failure recovery time is reached. That is, when When, and ATOSF>T.

[0093] in, represents the average failure time of the current processing node, T represents the fault repair time, and ATOSF represents the average failure time of all running nodes. It represents the mean failure time of the nth node in the mth subnet.

[0094] Optionally, the method can also determine the discrete time switching controller sequence according to the relationship between the mean failure time and the fault repair time satisfied by the node, satisfying

[0095] where σ is the discrete-time switching controller sequence.

[0096] The above technical solution, by constructing the system state transfer matrix space and finding the method to represent the average failure time of the system, can maximize the system out-of-control or downtime operation time under the action of the switching decision signal after the system is successfully invaded by the network, thereby buying valuable time for the administrator to repair the fault, reducing the economic losses caused by downtime or loss of control of the distributed industrial control system due to network intrusion, improving the intrusion tolerance protection capability of the distributed industrial control system, and increasing the time for system administrators to discover vulnerabilities and improve repairs.

[0097] The technical solution of this embodiment is to obtain the current processing node in the industrial control system and determine the current operating status data of the current processing node, and determine the current node state corresponding to the current processing node based on the current operating status data, so as to obtain at least one target node state in the industrial control system state transfer model based on the current node state. In the state transition probability matrix space of the industrial control system, the state transition probability matrix of the target industrial control system corresponding to the current processing node is obtained, and according to the state transition probability matrix of the target industrial control system, the expected value of the number of times the current processing node switches from the current node state to the out-of-service state through each target node state is calculated, and the state duration of the current processing node in each target node state is calculated, so as to calculate the average failure time corresponding to the current processing node according to the expected value of the number of times and the state duration corresponding to the current processing node, thereby screening out the target node whose average failure time is less than the failure repair time, and determining the failure time point and the failure repair time point corresponding to the target node according to the average failure time and the failure repair time, and then selecting at least one target candidate node from the candidate node set to replace the target node to continue running within the service interruption time period determined by the failure time point and the failure repair time point, thereby solving the problem that the existing industrial control system security protection method cannot effectively protect the industrial control system due to the inability to detect and prevent intrusion behaviors in real time and accurately, and can improve the fault operation time of the industrial control system, thereby effectively protecting the industrial control system and reducing the loss of the industrial control system caused by failure.

[0098] Embodiment III

[0099] Figure 6 is a schematic diagram of an industrial control system security protection device provided by Embodiment III of the present invention. As Figure 6 shown, the device includes: a mean time to failure determination module 610, a target node screening module 620, and a target alternative node replacement module 630, where:

[0100] The mean time to failure determination module 610 is configured to determine, according to an industrial control system state transition model and an industrial control system state transition probability matrix space, the mean time to failure that each working node in the industrial control system experiences from the current node state to the stopped service state;

[0101] The target node screening module 620 is configured to screen out target nodes whose mean time to failure is less than the fault repair time, and determine, according to the mean time to failure and the fault repair time, the fault time point and the fault repair time point corresponding to the target nodes;

[0102] The target alternative node replacement module 630 is configured to select at least one target alternative node from an alternative node set to replace the target node and continue to run during an interrupted service time period determined by the fault time point and the fault repair time point.

[0103] The technical solution of this embodiment determines, according to an industrial control system state transition model and an industrial control system state transition probability matrix space, the mean time to failure that each working node in the industrial control system experiences from the current node state to the stopped service state, and screens out target nodes whose mean time to failure is less than the fault repair time, so as to determine, according to the mean time to failure and the fault repair time, the fault time point and the fault repair time point corresponding to the target nodes, and further select at least one target alternative node from an alternative node set to replace the target node and continue to run during an interrupted service time period determined by the fault time point and the fault repair time point, solving the problem that the existing industrial control system security protection method cannot effectively protect the industrial control system because it cannot detect and prevent intrusion behaviors in real time and accurately, and can increase the fault operation time of the industrial control system, thereby effectively protecting the industrial control system and reducing the losses caused by faults in the industrial control system.

[0104] Optionally, the mean time to failure determination module 610 may be specifically configured to: collect historical operation status data of each node in the industrial control system; generate an industrial control system state transition model based on the historical operation status data, and establish an industrial control system state transition probability matrix corresponding to each node respectively to form an industrial control system state transition probability matrix space; wherein, the industrial control system state transition model includes a node state set and transition relationships between different node states in the node state set; each matrix element in the industrial control system state transition probability matrix is used to describe the transition probability of switching from one node state in the node state set to another node state.

[0105] Optionally, the mean time to failure determination module 610 may also be specifically configured to: obtain a current processing node in the industrial control system and determine the current operation status data of the current processing node; determine the current node state corresponding to the current processing node according to the current operation status data; obtain at least one target node state in the industrial control system state transition model according to the current node state; obtain a target industrial control system state transition probability matrix corresponding to the current processing node in the industrial control system state transition probability matrix space; calculate the expected value of the number of times the current processing node passes through each target node state when switching from the current node state to the stopped service state according to the target industrial control system state transition probability matrix; calculate the state duration of the current processing node in each target node state, and calculate the mean time to failure corresponding to the current processing node according to the expected value of the number of times and the state duration corresponding to the current processing node.

[0106] Optionally, the mean time to failure determination module 610 may be further configured to: calculate the expected value of the number of times the current processing node passes through each target node state when switching from the current node state to the stopped service state based on the following formula according to the target industrial control system state transition probability matrix:

[0107]

[0108]

[0109]

[0110]

[0111] Wherein, represents the expected value of the number of times the j-th node in the i-th subnet passes through the normal state when switching from the current node state to the stopped service state; represents the expected value of the number of times the j-th node in the i-th subnet passes through the vulnerable state when switching from the current node state to the stopped service state; Denote the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the attacked state; Denote the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the triggered state; Denote the probability that the j-th node in the i-th subnet transfers from the normal state to the vulnerable state; Denote the probability that the j-th node in the i-th subnet transfers from the vulnerable state to the attacked state; Denote the probability that the j-th node in the i-th subnet transfers from the attacked state to the triggered state.

[0112] Optionally, the mean time to failure determination module 610 can be further configured to: calculate the mean time to failure corresponding to the current processing node based on the following formula according to the expected number of times and the state duration corresponding to the current processing node:

[0113]

[0114] where l represents the target node state, and n represents the number of target node states, Denote the mean time to failure of the j-th node in the i-th subnet; Denote the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the target node state; Denote the state duration of the j-th node in the i-th subnet in the target node state.

[0115] Optionally, the target alternative node replacement module 630 can be specifically configured to: when the current system time point reaches the failure time point, select a target alternative node from the set of alternative nodes to continue running, and determine the mean time to failure that the target alternative node switches from the normal state to the stopped service state; determine the failure time point corresponding to the target alternative node according to the mean time to failure corresponding to the target alternative node; when the failure time point corresponding to the target alternative node does not reach the failure repair time point, return to execute when the current system time point reaches the failure time point, select a target alternative node from the set of alternative nodes to continue running until the failure time point corresponding to the target alternative node reaches the failure repair time point.

[0116] Optionally, the industrial control system can include a distributed industrial control system; the node states in the node state set can include the normal state, the vulnerable state, the attacked state, the waiting for improvement state, the triggered state, the stopped service state, the reduced service state, and the unknown damage state.

[0117] The industrial control system security protection device provided by the embodiments of the present invention can execute the industrial control system security protection method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0118] Embodiment 4

[0119] Figure 7 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular telephones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described herein and / or claimed.

[0120] As Figure 7 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0121] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0122] The processor 11 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the industrial control system security protection method.

[0123] In some embodiments, the industrial control system security protection method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the industrial control system security protection method described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute the industrial control system security protection method by any other suitable means (e.g., by means of firmware).

[0124] Various embodiments of the systems and techniques described above herein may be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: being implemented in one or more computer programs, which may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special or general-purpose programmable processor, and which may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0125] The computer program for implementing the method of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0126] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0127] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0128] The systems and techniques described herein can be implemented in a computing system that includes backend components (such as, for example, a data server), or a computing system that includes middleware components (such as, for example, an application server), or a computing system that includes frontend components (such as, for example, a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as, for example, a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0129] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0130] It should be understood that various forms of processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0131] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An industrial control system security protection method, characterized in that, Including: Determine the mean time to failure (MTTF) that each working node in the industrial control system experiences when switching from the current node state to the stopped service state, based on the industrial control system state transition model and the industrial control system state transition probability matrix space. Filter out the target nodes whose mean time to failure is less than the time to repair the failure, and determine the corresponding failure time point and time to repair the failure for the target nodes according to the mean time to failure and the time to repair the failure. During the interruption service time period determined by the failure time point and the time to repair the failure, select at least one target alternative node from the alternative node set to replace the target node and continue running. The step of selecting at least one target alternative node from the alternative node set to replace the target node and continue running during the interruption service time period determined by the failure time point and the time to repair the failure includes: When the current system time point reaches the failure time point, select a target alternative node from the alternative node set to continue running, and determine the mean time to failure that the target alternative node experiences when switching from the normal state to the stopped service state. Determine the failure time point corresponding to the target alternative node according to the mean time to failure corresponding to the target alternative node. When the failure time point corresponding to the target alternative node has not reached the time to repair the failure, return to execute the step of selecting a target alternative node from the alternative node set to continue running when the current system time point reaches the failure time point, until the failure time point corresponding to the target alternative node reaches the time to repair the failure.

2. The method according to claim 1, characterized in that Before determining the mean time to failure that each working node in the industrial control system experiences when switching from the current node state to the stopped service state, based on the industrial control system state transition model and the industrial control system state transition probability matrix space, it further includes: Collect the historical operation status data of each node in the industrial control system. Generate an industrial control system state transition model according to the historical operation status data, and establish an industrial control system state transition probability matrix corresponding to each node respectively to form an industrial control system state transition probability matrix space. Among them, the industrial control system state transition model includes a node state set and the transition relationships between different node states in the node state set. Each matrix element in the industrial control system state transition probability matrix is used to describe the transition probability of switching from one node state in the node state set to another node state.

3. The method according to claim 2, wherein The step of determining the mean time to failure that each working node in the industrial control system experiences when switching from the current node state to the stopped service state, based on the industrial control system state transition model and the industrial control system state transition probability matrix space, includes: Obtain the current processing node in the industrial control system, and determine the current operation status data of the current processing node. Determine the current node state corresponding to the current processing node according to the current operation status data. Obtain at least one target node state in the industrial control system state transition model according to the current node state. In the industrial control system state transition probability matrix space, obtain the target industrial control system state transition probability matrix corresponding to the current processing node. Calculate the expected value of the number of times that the current processing node passes through each of the target node states when switching from the current node state to the stopped service state according to the target industrial control system state transition probability matrix; Calculate the state duration of the current processing node in each of the target node states, and calculate the mean time to failure corresponding to the current processing node according to the expected value of the number of times and the state duration corresponding to the current processing node.

4. The method according to claim 3, wherein The calculating the expected value of the number of times that the current processing node passes through each of the target node states when switching from the current node state to the stopped service state according to the target industrial control system state transition probability matrix includes: Based on the following formula, calculate the expected value of the number of times that the current processing node passes through each of the target node states when switching from the current node state to the stopped service state according to the target industrial control system state transition probability matrix: Among them, represents the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the normal state; represents the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the vulnerable state; represents the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the attacked state; represents the expected number of times that the j-th node in the i-th subnet switches from the current node state to the stopped service state through the triggered state; represents the probability that the j-th node in the i-th subnet transfers from the normal state to the vulnerable state; represents the probability that the j-th node in the i-th subnet transfers from the vulnerable state to the attacked state; represents the probability that the j-th node in the i-th subnet transfers from the attacked state to the triggered state.

5. The method according to claim 3, wherein The calculating the mean time to failure corresponding to the current processing node according to the expected value of the number of times and the state duration corresponding to the current processing node includes: Based on the following formula, calculate the mean time to failure corresponding to the current processing node according to the expected value of the number of times and the state duration corresponding to the current processing node: where \(l\) represents the target node state and \(n\) represents the number of target node states. represents the mean time to failure of the \(j\)-th node in the \(i\)-th subnet; represents the expected number of times that the \(j\)-th node in the \(i\)-th subnet passes through the target node state when switching from the current node state to the stopped service state; represents the duration of the state of the \(j\)-th node in the \(i\)-th subnet in the target node state.

6. The method according to any one of claims 2-5, characterized in that The industrial control system includes a distributed industrial control system; The node states in the node state set include a normal state, a vulnerable state, an attacked state, a waiting for improvement state, a triggered state, a stopped service state, a degraded service state, and an unknown damage state.

7. An industrial control system security protection device, characterized in that, including: A mean time to failure determination module, configured to determine the mean time to failure that each working node in the industrial control system passes through when switching from the current node state to the stopped service state according to the industrial control system state transition model and the industrial control system state transition probability matrix space; A target node screening module, configured to screen out target nodes whose mean time to failure is less than the fault repair time, and determine the fault time point and the fault repair time point corresponding to the target node according to the mean time to failure and the fault repair time; A target alternative node replacement module, configured to select at least one target alternative node from the set of alternative nodes to replace the target node to continue running during the interrupt service time period determined by the fault time point and the fault repair time point; The target alternative node replacement module is specifically configured to: when the current system time point reaches the fault time point, select a target alternative node from the set of alternative nodes to continue running, and determine the mean time to failure that the target alternative node passes through when switching from the normal state to the stopped service state; Determine the fault time point corresponding to the target alternative node according to the mean time to failure corresponding to the target alternative node; When the fault time point corresponding to the target alternative node does not reach the fault repair time point, return to execute when the current system time point reaches the fault time point, select a target alternative node from the set of alternative nodes to continue running until the fault time point corresponding to the target alternative node reaches the fault repair time point.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the industrial control system security protection method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for implementing the industrial control system security protection method according to any one of claims 1-6 when the computer instructions are executed by a processor.

Citation Information

Patent Citations

  • Method and apparatus for dynamic node healing in a multi-node environment

    CN105204965A

  • Self-healing method based on cognition and access point cooperation in ultra-dense network

    CN109413680A