A safety protection system and method for a DCS system of a thermal power unit
By deploying network auditing, firewalls, and a security management center in the DCS system of thermal power units, combined with identity authentication and intrusion detection, the problem of insufficient security protection in the DCS system has been solved, and real-time monitoring and compliant network security protection capabilities have been achieved.
Patent Information
- Application Number
- CN202111419817.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-26
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2041-11-26
AI Technical Summary
In existing technologies, the DCS system of thermal power units lacks dedicated security protection, making it a primary target and entry point for cyberattacks. It fails to effectively detect and prevent cyberattacks, and does not achieve identity authentication, data integrity verification, and security management, thus failing to meet compliance requirements.
Deploy network auditing, firewalls, and IDS devices in the DCS system, implement host security hardening, establish a security management center, separate the management network and business network through a self-organizing network, and adopt industrial firewalls, MAC-switch port binding, intrusion detection devices, combined with identity authentication, vulnerability scanning and whitelist management to achieve centralized management and real-time monitoring of security policies.
It enhances the network security protection capabilities of the DCS system, enabling timely detection and blocking of malicious programs, recording of abnormal situations, meeting national and industry compliance requirements, and ensuring the safe and stable operation of the system.
Smart Images

Figure CN114625074B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of protection of distributed control system of thermal power unit, and particularly relates to a security protection system and method for DCS system of thermal power unit. BACKGROUND
[0002] Today is a global information communication era, and information communication technology environment develops rapidly, and human beings have entered the digital era, and information has become the strategic resource that can represent the comprehensive national power. Information communication technology has become a new factor for social sustainable development. However, with the rapid development and popularization of the Internet, computer viruses, Trojan horses, hackers and other malicious network attacks are increasingly frequent, and the power system has become an important target of penetration attacks. There is no special security protection system for the DCS system of the thermal power unit, so it becomes a main attack target and breakthrough. SUMMARY
[0003] In order to solve the problems in the prior art, the present application provides the following technical solutions, the network security of the unit DCS system is reformed, the switch supporting port mirroring is replaced, the network audit, log audit, IDS, firewall and other devices are added, and the security reinforcement is implemented on the host such as the engineer station; The host security protection and reinforcement software is deployed on the industrial host such as the workstation and server of the unit DCS system, the functions such as identity authentication, access control, security audit, intrusion prevention and malicious code prevention are realized, and the security policy of the operating system itself is enabled, the security of the operating system itself is improved and audited and recorded; The security management center is established in the unit DCS system, the log audit system and the security management platform are deployed, the management and operation and log collection and analysis of all network devices and security devices are realized; At the same time, through the way of ad hoc network, and deploying the firewall on the communication link between the host installed with the host security protection and reinforcement software and the security management center, the separation of the management network and the business network is realized, and the network security of the system is further ensured.
[0004] The present application provides a security protection system for DCS system of thermal power unit, which comprises:
[0005] A communication network security protection subsystem is used for ensuring the safety of the communication process and communication data of the DCS system;
[0006] A security area boundary security protection subsystem is used for checking or limiting the internal and external network behaviors, detecting, preventing and limiting the network attack behaviors, analyzing the network behaviors, recording and alarming the attack information, performing security audit and performing trusted verification on the boundary device;
[0007] The secure computing environment security protection subsystem is used for user authentication, regular backup of audit logs, detection, identification, and alarm for intrusion behaviors and viruses at critical nodes, dynamic trusted verification of application execution, verification of data transmission and storage integrity, and off-site real-time backup; and
[0008] The security management center is used by system administrators to perform system management operations and audit operation records through commands or an interface, and by audit administrators to perform security audit operations and audit operation records through commands or an interface. It allows for the setting of specific management areas and security information transmission paths to control security devices or components distributed throughout the network; centralized monitoring of the operational status of network links, security devices, network equipment, and servers; aggregation and analysis of device audit data; management of security policies, malicious code, and patch upgrades; and detection, identification, and alerting of security events in the network.
[0009] in:
[0010] The secure zone boundary security protection subsystem includes: a boundary protection and access control module, an intrusion prevention and malicious code prevention module, and a security audit module; the secure computing environment security protection subsystem includes: an identity authentication and access control module, and a security audit and intrusion prevention module.
[0011] In a preferred embodiment, the boundary protection and access control module includes:
[0012] (1) An industrial firewall is deployed at the boundary between the DCS system and the SIS system to realize the functions of logical isolation, packet filtering and access control. At the same time, it performs deep inspection on the transmitted packets, detects abnormal behavior in a timely manner and blocks or alarms them. The industrial firewall also serves as a redundant protection measure for the current one-way isolation device.
[0013] (2) Host security protection submodule, which is installed in software on the engineer station, historical station and operator station of the DCS system to check and restrict unauthorized external connections of DCS system users, and restrict USB, optical drive and serial port;
[0014] (3) MAC-switch port binding submodule: binds MAC-switch ports to restrict unauthorized devices from connecting to the DCS network.
[0015] In a preferred embodiment, the intrusion prevention and malicious code prevention module includes:
[0016] (1) Intrusion detection device or industrial control network security monitoring and auditing device, deployed on the DCS system, for detecting various network behaviors and malicious codes in the DCS system network, preventing and limiting network attack behaviors initiated from the inside of the DCS system;
[0017] (2) Intrusion prevention device, deployed at the boundary of the DCS system and SIS, for detecting, preventing and limiting network attack behaviors initiated from the outside;
[0018] As a preferred embodiment, the security auditing module comprises:
[0019] Industrial control network monitoring and auditing device, deployed in the DCS system, for monitoring and analyzing network behaviors, and auditing important user behaviors and important security events.
[0020] As a preferred embodiment, the identity authentication and access control module comprises:
[0021] Identity authentication submodule, for authenticating the identity of the host with high importance and responsible engineers and historians using two or more than two combined authentication technologies of password, code and biotechnology, the identity authentication submodule being installed in the host security protection software.
[0022] As a preferred embodiment, the security auditing and intrusion prevention module comprises:
[0023] (1) Vulnerability scanning and testing and repairing submodule, for periodically carrying out vulnerability scanning on the DCS system, discovering possible vulnerabilities in the system in time, and repairing after sufficient testing and evaluation;
[0024] (2) Security protection submodule, for being installed in the form of software on the host of the engineer station, historian station and operator station of the DCS system, for detecting intrusion behaviors in time and alarming;
[0025] (3) Malicious code prevention submodule, the malicious code prevention submodule being arranged in the host security protection submodule and installed on the host of the engineer station, historian station and operator station of the DCS system, the malicious code prevention submodule being generated based on a white list, for discovering and blocking viruses and other malicious codes in time;
[0026] (4) Special security U disk, configured for the DCS system, for backing up data of the DCS system in time, and focusing on managing the USB port used for data backup.
[0027] As a preferred embodiment, the security management center comprises:
[0028] (1) a sub-module for separately networking in a domain, used for deploying a firewall device between a DCS network, only allowing safe management related traffic to pass, and controlling and managing security devices or security components distributed in the network through the security management center;
[0029] (2) a security policy management sub-module, used for centrally managing the security policy of the host security protection, including port management, security reinforcement measures, malicious code protection, whitelist management, peripheral control, and patch upgrade;
[0030] (3) a log auditing device, used for centrally collecting, summarizing, and analyzing and displaying log information generated by hosts, network devices, security devices, and application systems distributed in different locations;
[0031] (4) a unified security management platform, used for centrally monitoring and managing the device running status of the host security management, log management, industrial control network security monitoring and auditing device, firewall, and intrusion prevention device, and uniformly displaying alarm information and security events.
[0032] In a second aspect of the present application, a method for security protection of a thermal power unit DCS system is provided, comprising:
[0033] Communication network security protection, implementing security guarantee of DCS system communication process and communication data;
[0034] Security area boundary security protection, checking or limiting internal and external network behaviors, detecting, preventing, and limiting network attack behaviors, analyzing network behaviors, recording and alarming attack information, performing security auditing, and performing trusted verification on boundary devices;
[0035] Security computing environment security protection, identifying the identity of a user, regularly backing up audit records, detecting and identifying and alarming viruses and intrusion behaviors of important nodes, dynamically verifying the execution link of an application program, checking the integrity of data transmission and storage, and performing real-time backup in a different place; and
[0036] Adding a security management center, so that a system administrator performs system management operation through a command or an operation interface and audits operation records, and an auditing administrator performs security auditing operation through a command or an operation interface and audits operation records; setting a specific management area and a security information transmission path, so as to control and manage security devices or security components distributed in the network; centrally monitoring the running status of network links, security devices, network devices, and servers; summarizing and analyzing audit data of the devices, managing security policies, malicious codes, and patch upgrades, detecting and identifying and alarming security events in the network.
[0037] The third aspect of the present application provides an electronic device comprising a processor and a memory, the memory storing a plurality of instructions, and the processor being configured to read the instructions and perform the method according to the second aspect.
[0038] The fourth aspect of the present application provides a computer-readable storage medium storing a plurality of instructions, the plurality of instructions being readable by a processor and executable to perform the method according to the second aspect.
[0039] The present application has the following beneficial effects:
[0040] By implementing the network security protection upgrade project for the DCS system, the self-protection capability of the DCS system is greatly enhanced. The network security facility can timely detect and discover possible network insecurity events, can block the execution of malicious programs, and can timely issue alarm information to prompt the operation and maintenance personnel to further check and handle when some abnormal conditions occur. The log information before and after the occurrence of the insecurity event can be recorded, which is convenient for subsequent event disposal and analysis. In summary, the security protection capability of the DCS system is improved.
[0041] The network security protection measures of the DCS system are upgraded, so that the DCS system has the functions of real-time monitoring of network security operation state, resisting malicious attack behavior, recording system network behavior, etc., and the security protection capability of the DCS system is improved, so as to guarantee the safe and stable operation of the DCS system. At the same time, the safety protection measures meet the requirements of various policies and regulations of the state and the industry, and realize the legal and compliant operation of the DCS system. BRIEF DESCRIPTION OF DRAWINGS
[0042] Figure 1 It is a network structure diagram of a general DCS architecture according to the prior art.
[0043] Figure 2 It is a basic network topology diagram of a DCS system provided by the present application.
[0044] Figure 3 It is a basic network topology diagram of a DCS system provided by the present application, which is added with a security protection system.
[0045] Figure 4 It is a structure schematic diagram of an electronic device provided by the present application. DETAILED DESCRIPTION
[0046] In order to better understand the above technical solutions, the above technical solutions will be described in detail in combination with the drawings of the specification and specific embodiments.
[0047] The method provided by the application can be implemented in a terminal environment, which can include one or more of the following components: a processor, a memory, and a display screen. The memory stores at least one instruction, which is loaded and executed by the processor to implement the method described in the following embodiments.
[0048] The processor can include one or more processing cores. The processor connects various parts in the entire terminal through various interfaces and lines, and performs various functions of the terminal and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory, and calling data stored in the memory.
[0049] The memory can include random access memory (RAM) and read-only memory (ROM). The memory can be used to store instructions, programs, codes, code sets or instructions.
[0050] The display screen is used to display the user interface of various application programs.
[0051] In addition, those skilled in the art can understand that the structure of the terminal described above does not constitute a limitation on the terminal, and the terminal can include more or fewer components, or combine certain components, or different component arrangements. For example, the terminal also includes radio frequency circuitry, an input unit, a sensor, audio circuitry, a power supply, and the like, which are not described here.
[0052] The embodiment of the application carries out network security reconstruction on the unit DCS system, replaces the switch supporting port mirroring, adds network audit, log audit, IDS, firewall and other devices, and implements security reinforcement on the host such as the engineer station; host security protection and reinforcement software are deployed on the industrial host such as the unit DCS system workstation and server, to realize functions such as identity authentication, access control, security audit, intrusion prevention, and malicious code prevention, and the security policy of the operating system itself is enabled to realize the improvement and audit and record of the security of the operating system itself; a security management center is established in the unit DCS system, log audit systems and security management platforms are deployed to realize the management and operation and log collection and analysis of all network devices and security devices; at the same time, a firewall is deployed on the communication link between the host installed with the host security protection and reinforcement software and the security management center in an ad hoc network mode, to realize the separation of the management network and the business network, and further ensure the network security of the system.
[0053] Generally, the DCS system application is a vertical layered network structure, from top to bottom, the process monitoring layer, the field control layer and the field device layer. The layers are connected by the communication network, and the devices in the layer communicate with each other through the communication network of the level, and the typical network structure is as follows Figure 1As shown in the figure, wherein:
[0054] (1) Process monitoring layer: including control server (redundant control server), historical data station, engineer station, operator station, connected equipment and host interface, mainly for operation monitoring, and has part of management function. This level is for operators and control system engineers, so this level is equipped with technical means of computer system and various external devices, especially display and keyboard; in addition, it needs large storage capacity of hard disk or floppy disk support; in addition, it needs strong software support to ensure that engineers and operators configure, monitor and operate the system, implement advanced control strategy, fault diagnosis and quality evaluation on the production process;
[0055] (2) Field control layer: field control layer includes multiple controllers, the main functions include collecting process data, data conversion and processing, monitoring and controlling the production process, outputting control signals to realize analog and switching value control; diagnosing I / O cards; communicating with process monitoring layer and the like;
[0056] (3) Field device layer: including various field instruments, the main functions of field device layer include collecting control signals, executing control commands and performing device actions according to control signals.
[0057] In this embodiment, the DCS system is located in the safety I area of the production control area, and its main bearing business is distributed control, centralized operation and hierarchical management. It is a multi-level computer system composed of process control level and process monitoring level with communication network as the link, and each computer in the system communicates in the way of local area network, and transmits real-time information. A thermal power plant has multiple sets of DCS systems, and the manufacturers are Emerson. Some of the unit DCS system host operating systems use Unix, and the rest use Windows operating system. Multiple sets of DCS systems are networked independently, and there is no network connection between the DCS systems of each unit. The current security protection status and existing problems are as follows:
[0058] (1) Safe physical environment
[0059] The DCS system room is located in the electronic room of the main plant, the physical location of the electronic room meets the requirements of the selection of the machine room, the electronic door access system is set at the entrance of the electronic room, and the video monitoring camera is installed at the entrance and inside the electronic room. The main equipment in the electronic room is fixed in the cabinet, and the communication cable is laid in the cable trench; the cabinets, facilities and equipment in the electronic room are subjected to safety grounding treatment. The electronic room is provided with an automatic fire extinguishing system, which can realize automatic fire detection, automatic alarm and automatic extinguishing, and the machine room uses a special air conditioner to control the temperature of the machine room. The equipment in the electronic room adopts double power supply, and the UPS can supply power for at least 2 hours or more in the case of power failure. Therefore, there is no security protection problem.
[0060] (II) Secure communication network
[0061] The network architecture of the DCS system is reasonable, the performance of network equipment and network bandwidth meet the demand of peak business, and the key equipment and links are all redundant.
[0062] Problems:
[0063] (1) No check technology or cryptographic technology is used to ensure the integrity of data in the communication process;
[0064] (2) No cryptographic technology is used to ensure the confidentiality of data in the communication process;
[0065] (3) No trusted root-based trusted verification is used for the communication process.
[0066] (III) Security area boundary
[0067] The DCS system is individually networked for each unit, and has horizontal boundaries with the SIS system and the vibration acquisition system. Forward isolation devices are deployed at the horizontal boundaries, and access control rules are set for the security isolation devices. Except for allowing communication, all communications are denied. The DCS system has no vertical connection.
[0068] Problems:
[0069] (1) No check or restriction is made on the behavior of unauthorized equipment connecting to the internal network privately;
[0070] (2) No check or restriction is made on the behavior of internal users connecting to the external network unauthorizedly;
[0071] (3) No detection, prevention or restriction is made on the network attack behavior initiated from the outside at the key network nodes;
[0072] (4) No detection, prevention or restriction is made on the network attack behavior initiated from the inside at the key network nodes;
[0073] (5) No technical measures are taken to analyze the network behavior;
[0074] (6) The attack behavior cannot be detected, the attack information cannot be recorded, and the alarm cannot be provided;
[0075] (7) No security audit is made at the network boundary and important network nodes;
[0076] (8) No trusted verification is made on the boundary equipment.
[0077] (IV) Secure computing environment
[0078] The DCS system operator station and engineer station identify and authenticate the identity of the user logging in, different users have different operation permissions, and redundant and expired accounts are deleted. The log function is enabled on each host and the DCS system, which can record the operations of the operating system and the DCS system. The host has closed unnecessary system services and high-risk ports. The data of the DCS system is backed up regularly, and the backup data is stored off-site.
[0079] Problems:
[0080] (1) The user's identity is not authenticated by two or more than two combined authentication technologies such as password, password technology, and biotechnology;
[0081] (2) The audit record is not backed up regularly;
[0082] (3) It is impossible to discover possible known vulnerabilities in time, and it is impossible to test and repair in time;
[0083] (4) It is impossible to detect the intrusion behavior of important nodes, and it is impossible to provide alarm when serious intrusion events occur;
[0084] (5) Malicious code prevention software is not installed, and it is impossible to identify intrusion and virus behavior in time;
[0085] (6) Dynamic trusted verification is not performed at the key execution link of the application program;
[0086] (7) Verification technology is not used to ensure the integrity of important data during transmission and storage;
[0087] (8) The function of real-time backup of data in different places is not provided.
[0088] (Five) Security Management Center
[0089] The DCS system does not configure a security management center.
[0090] Problems:
[0091] (1) The system administrator does not realize system management operation through a specific command or operation interface, and the operation record is not audited;
[0092] (2) The audit administrator does not realize security audit operation through a specific command or operation interface, and the operation record is not audited;
[0093] (3) The security administrator does not realize security management operation through a specific command or operation interface, and the operation record is not audited;
[0094] (4) No specific management area is divided, and no safe information transmission path is established to control the security devices or security components distributed in the network;
[0095] (5) Network link, security device, network device and server operation status are not monitored centrally;
[0096] (6) Audit data distributed on each device is not collected, aggregated and centrally analyzed;
[0097] (7) Security policy, malicious code, patch upgrade and other security-related matters are not centrally managed;
[0098] (8) Various security events occurring in the network are not identified and alarmed.
[0099] As shown in Figure 3 , the embodiment provides a power plant DCS system security protection system, comprising:
[0100] A communication network security protection subsystem for ensuring DCS system communication process and communication data security;
[0101] A security area boundary security protection subsystem for checking or limiting internal and external network behavior, detecting, preventing and limiting network attack behavior, analyzing network behavior, recording and alarming attack information, performing security audit and conducting trusted verification on boundary devices;
[0102] A secure computing environment security protection subsystem for user identity authentication, regular backup of audit records, detection, identification and alarm of important node intrusion behavior and viruses, dynamic trusted verification of application program execution links, data transmission and storage integrity verification and off-site real-time backup; and
[0103] A security management center for system administrator to perform system management operation through command or operation interface and audit operation records, and for audit administrator to perform security audit operation through command or operation interface and audit operation records; setting specific management area and security information transmission path to control distributed network security devices or security components; centrally monitoring network link, security device, network device and server operation status; aggregating and analyzing device audit data, managing security policy, malicious code and patch upgrade, detecting, identifying and alarming network security events;
[0104] Wherein:
[0105] The security area boundary security protection subsystem comprises a boundary protection and access control module, an intrusion prevention and malicious code prevention module and a security audit module; the secure computing environment security protection subsystem comprises an identity authentication and access control module, a security audit and intrusion prevention module.
[0106] As a preferred embodiment, the boundary protection and access control module comprises:
[0107] (1) an industrial firewall, deployed at the boundary of the DCS system and the SIS system, for realizing the functions of logical isolation, message filtering, access control, and simultaneously performing deep inspection on the transmitted messages, discovering abnormal behaviors in time and blocking or alarming;
[0108] (2) a host security protection sub-module, installed in the form of software on the engineer station, the historian station and the operator station of the DCS system, for checking and limiting the illegal external connection of the DCS system user, and limiting the USB, optical drive and serial port.
[0109] (3) a MAC-switch port binding sub-module, for binding the MAC-switch ports and limiting the behavior of unauthorized equipment privately connecting to the DCS network.
[0110] As a preferred embodiment, the intrusion prevention and malicious code prevention module comprises:
[0111] (1) an intrusion detection device or an industrial network security monitoring and auditing device, deployed on the DCS system, for detecting various network behaviors and malicious codes in the DCS system network, and preventing and limiting the network attack behaviors initiated from the inside of the DCS system;
[0112] (2) an intrusion prevention device, deployed at the boundary of the DCS system and the SIS, for detecting, preventing and limiting the network attack behaviors initiated from the outside;
[0113] As a preferred embodiment, the security auditing module comprises:
[0114] an industrial network monitoring and auditing device, deployed in the DCS system, for monitoring and analyzing the network behaviors, and auditing the behaviors of important users and important security events.
[0115] As a preferred embodiment, the identity authentication and access control module comprises:
[0116] an identity authentication sub-module, for performing identity authentication on the engineer station and the historian station with high importance by using two or more than two combined authentication technologies of password, code technology and biological technology, and the identity authentication sub-module is installed in the host security protection software.
[0117] As a preferred embodiment, the security auditing and intrusion prevention module comprises:
[0118] (1) a vulnerability scanning test patching submodule, configured to periodically perform vulnerability scanning on the DCS system, to timely find possible vulnerabilities in the system, and to perform patching after sufficient testing and evaluation;
[0119] (2) a security protection submodule, configured in the form of software to be installed on host computers of the engineer station, the historian station, and the operator station of the DCS system, to timely detect intrusion behaviors and alarm;
[0120] (3) a malicious code prevention submodule, configured in the host security protection submodule and installed on the host computers of the engineer station, the historian station, and the operator station of the DCS system, the malicious code prevention submodule being generated based on a white list, to timely find and block malicious codes such as viruses;
[0121] (4) a special security U disk, configured for the DCS system, to timely back up data of the DCS system and focus on managing the USB port used for data backup.
[0122] As a preferred embodiment, the security management center comprises:
[0123] (1) a domain-specific separate networking submodule, configured to deploy a firewall device between the DCS network, to only allow security management related traffic to pass, and to control the security devices or security components distributed in the network through the security management center;
[0124] (2) a security policy management submodule, configured to centrally manage the security policies of port management, security reinforcement measures, malicious code protection, white list management, peripheral control, and patch upgrade of the host security protection;
[0125] (3) a log auditing device, configured to centrally collect, aggregate, and analyze and display log information generated by the host, the network device, the security device, and the application system distributed in different locations;
[0126] (4) a unified security management platform, configured to centrally monitor and manage the device running status of the host security management, the log management, the industrial control network security monitoring and auditing device, the firewall, and the intrusion prevention device, and to uniformly display alarm information and security events.
[0127] The security protection system is applied to a basic DCS system and a typical network topology as shown in Figure 2 , wherein the basic DCS system and the typical network topology as shown in Figure 2 comprise:
[0128] The process monitoring layer network of the DCS system is provided with a root switch and a root backup switch, the root switch and the root backup switch are interconnected, and the root switch and the root backup switch are configured in redundancy; two access switches are configured in a group, and the two access switches are connected with the root switch and the root backup switch respectively, so that device redundancy and link redundancy are provided; the controller, the operator station and the engineer station are connected with the two access switches respectively, and redundancy is realized on the links.
[0129] The DPU communicates with field devices through input and output cards, and realizes collection of running data of the field devices and transmission of control commands.
[0130] The setting principles of the system include:
[0131] (1) Safety
[0132] The safety measures of the security upgrade should not have an adverse effect on the basic functions of the DCS system. When considering the security upgrade scheme, the continuity of field business must be ensured first, and the DCS system delay or system response time should not be affected due to security upgrade. The basic functions of the DCS system should not be interrupted when the safety measures fail. The new security risks generated due to security upgrade are analyzed and preventive measures are taken.
[0133] (2) Compliance
[0134] Firstly, it is necessary to meet the requirements of national laws and regulations and industry supervision. It is necessary to meet the general requirements of the Network Security Law, meet the requirements of Basic Requirements for Network Security Protection (GB / T 22239-2019), Basic Requirements for Security Protection of Key Information Infrastructure (draft for submission), and General Security Protection Scheme and Evaluation Specification for Power Monitoring System Security Protection (Guo Neng Anquan
[2015] No. 36).
[0135] (3) Moderate protection
[0136] As a special network of power generation enterprises, the security protection of the DCS system is quite different from other information systems connected with the Internet. In the process of building the information security defense system, the security risks faced are analyzed in detail, mainly for the protection of the DCS system, focusing on the protection of the boundary, and highlighting the principle of moderate protection. On the premise of considering availability and construction cost, the existing security protection measures are modified and upgraded.
[0137] (4) Technical management
[0138] When formulating the technical measures for the security protection upgrade of the DCS system, the relevant management measures should also be considered, and the technical measures and the management measures should be combined. In certain cases, the effectiveness of the technical measures should be guaranteed by relying on the management measures, and the deficiencies of the technical measures should be made up by relying on the management measures, so as to improve the overall security of the DCS system.
[0139] (5) Dynamic adjustment
[0140] The network security problem is not static, and it will change with the change of the management related organizational structure, organizational strategy, information system and operation process, and it will also change with the adjustment of the equipment of the DCS system and the development of the network technology. Therefore, the various changes of the DCS system must be tracked, and the security protection strategy and measures must be adjusted in time to adapt to the change of the power monitoring system.
[0141] (6) Self-controllable
[0142] In the case of selection, the DCS system and the security protection facilities thereof should give priority to the use of high-security products, reduce the uncontrollable security risks of the products, and build the power monitoring system meeting the requirements of the high-security level system.
[0143] (7) Advanced
[0144] With the rapid development of information technology, the invasion and penetration technology for the information system is gradually becoming professional, and the security protection of the DCS system must have a certain degree of advancement, so as to resist the invasion and attack behavior of the power monitoring system in the future period, and the upgrade scheme needs to have a certain degree of foresight, so as to meet the current increasingly complex compliance construction demand.
[0145] In a second aspect of the present application, a method for security protection of a thermal power unit DCS system is provided, comprising:
[0146] Communication network security protection, implementing security guarantee of DCS system communication process and communication data;
[0147] Security area boundary security protection, checking or limiting internal and external network behavior, detecting, preventing and limiting network attack behavior, analyzing network behavior, recording and alarming attack information, performing security audit and performing trusted verification on boundary equipment;
[0148] Security computing environment security protection, performing identity authentication on users, regularly backing up audit records, detecting and identifying and alarming virus and intrusion behavior of important nodes, performing dynamic trusted verification on execution links of application programs, checking data transmission and storage integrity and real-time backup in different places; and
[0149] A security management center is added, enabling system administrators to perform system management operations and audit operation records through commands or an interface, and audit administrators to perform security audit operations and audit operation records through commands or an interface. Specific management areas and security information transmission paths are set up to control security devices or security components distributed in the network. The operation status of network links, security devices, network devices, and servers is centrally monitored. Audit data from devices is summarized and analyzed, security policies, malicious code, and patch upgrades are managed, and security events in the network are detected, identified, and alerted.
[0150] The present invention also provides a memory that stores a plurality of instructions for implementing the methods as described in the embodiments.
[0151] like Figure 4 As shown, the present invention also provides an electronic device, including a processor 301 and a memory 302 connected to the processor 301. The memory 302 stores a plurality of instructions, which can be loaded and executed by the processor to enable the processor to perform the methods as described in the embodiments.
[0152] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if these modifications and modifications of the invention fall within the scope of the claims and their equivalents, the invention is also intended to include these modifications and modifications.
Claims
1. A safety protection system for a thermal power unit DCS system, characterized in that Comprise: A communication network security protection subsystem for ensuring the security of the communication process and communication data of the DCS system; A security area boundary security protection subsystem for checking or limiting internal and external network behavior, detecting, preventing and limiting network attack behavior, analyzing network behavior, recording and alarming attack information, performing security auditing, and performing trusted verification on boundary devices; A secure computing environment security protection subsystem for authenticating users, regularly backing up audit records, detecting and identifying and alarming viruses and intrusion behavior on important nodes, dynamically verifying the execution of application programs, checking the integrity of data transmission and storage, and performing real-time backup in different locations; And A security management center for system administrators to perform system management operations through a command or operation interface and audit operation records, and for audit administrators to perform security auditing operations through a command or operation interface and audit operation records; setting specific management areas and secure information transmission paths to control and manage security devices or security components distributed in the network; centrally monitoring the operating status of network links, security devices, network devices, and servers; Summarizing and analyzing audit data of devices, managing security policies, malicious codes, and patch upgrades, detecting and identifying security events in the network and alarming; Wherein: The security area boundary security protection subsystem comprises a boundary protection and access control module, an intrusion prevention and malicious code prevention module, and a security audit module; the secure computing environment security protection subsystem comprises an identity authentication and access control module, a security audit and intrusion prevention module; The boundary protection and access control module comprises: (1) An industrial firewall deployed at the boundary of the DCS system and the SIS system for implementing logical isolation, message filtering, and access control functions, while performing deep inspection on transmitted messages to timely detect abnormal behavior and block or alarm; the industrial firewall also serves as a redundant protection measure for the current one-way isolation device; (2) A host security protection submodule installed in the form of software on the engineer station, historian station, and operator station of the DCS system to check and limit illegal external connections of DCS system users, and to limit USB, optical drive, and serial ports; (3) A MAC-switch port binding submodule that binds MAC-switch ports to limit unauthorized devices from connecting to the DCS network.
2. The system according to claim 1, characterized in that The intrusion prevention and malicious code prevention module comprises: (1) An intrusion detection device or industrial network security monitoring and auditing device deployed on the DCS system to detect various network behaviors and malicious codes in the DCS system network and prevent and limit network attack behavior initiated from within the DCS system; (2) An intrusion prevention device deployed at the boundary of the DCS system and the SIS for detecting, preventing, and limiting network attack behavior initiated from the outside.
3. The system as claimed in claim 1, wherein The security audit module comprises: The industrial control network monitoring and auditing device is deployed in the DCS system to monitor and analyze network behaviors and to audit important user behaviors and important security events.
4. The system according to claim 1, wherein The identity authentication and access control module comprises: An identity authentication submodule for authenticating the identity of a host with a high importance and a person in charge of an engineer station and a historian station by using an authentication technology combining two or more of password, code and biological technologies, and the identity authentication submodule is installed in a host security protection software.
5. The system as claimed in claim 1, wherein The security auditing and intrusion prevention module comprises: (1) a vulnerability scanning and testing and repairing submodule for periodically performing vulnerability scanning on the DCS system to find possible vulnerabilities in the system in time and repairing the vulnerabilities after sufficient testing and evaluation; (2) a security protection submodule in the form of software installed on the host computers of the engineer station, historian station and operator station of the DCS system for detecting intrusion behaviors in time and alarming; (3) a malicious code prevention submodule provided in the host security protection submodule and installed on the host computers of the engineer station, historian station and operator station of the DCS system, the malicious code prevention submodule is generated based on a white list and is used to find and block malicious codes in time; (4) a special security U disk configured for the DCS system for backing up data of the DCS system and focusing on the management of a USB port used for data backup.
6. The system as claimed in claim 1, wherein The security management center comprises: (1) a sub-domain separate networking submodule for deploying a firewall device between the DCS network to allow only the flow related to security management to pass through, and controlling and managing the security devices or security components distributed in the network through the security management center; (2) a security policy management submodule for centrally managing the security policies of the host security protection, such as port management, security reinforcement measures, malicious code protection, white list management, peripheral control and patch upgrade; (3) a log auditing device for centrally collecting, summarizing and analyzing the log information generated by the host computers, network devices, security devices and application systems distributed in different locations and displaying the log information; (4) a unified security management platform for centrally monitoring and managing the running status of the host security management, log management, industrial control network security monitoring and auditing device, firewall and intrusion prevention device, and uniformly displaying the alarm information and security events.
7. The security protection method for the DCS system of a thermal power unit according to any one of claims 1-6, characterized in that It comprises: Communication network security protection for implementing the security guarantee of the communication process and communication data of the DCS system; Security area boundary security protection for checking or limiting the internal and external network behaviors, detecting, preventing and limiting network attack behaviors, analyzing network behaviors, recording and alarming attack information, performing security auditing and performing trusted verification on boundary devices; Security computing environment security protection for authenticating the identity of a user, regularly backing up audit records, detecting and identifying and alarming the intrusion behaviors and viruses of important nodes, dynamically verifying the execution link of an application program, checking the integrity of data transmission and storage and performing real-time backup in a different place; and The security management center is added, so that the system administrator performs system management operation through a command or an operation interface and audits operation record, the audit administrator performs security audit operation through a command or an operation interface and audits operation record, a specific management area and a security information transmission path are set, so that the security equipment or security component distributed in the network is controlled, and the running conditions of the network link, the security equipment, the network equipment and the server are centrally monitored; The audit data of the equipment is summarized and analyzed, the security policy, the malicious code and the patch upgrade are managed, the security event in the network is detected, identified and alarmed.
8. An electronic device, comprising: The computer readable storage medium stores a plurality of instructions, and the plurality of instructions can be read and executed by the processor to perform the method in claim 7.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a plurality of instructions, and the plurality of instructions can be read and executed by the processor to perform the method in claim 7.
Citation Information
Patent Citations
Distributive management system of information network security for power enterprises
CN103227797A