A secure simulation method for industrial control systems based on lightweight virtualization

Through lightweight virtualization technology, the five-layer structure of the industrial control system is simulated, combined with hardware PLC and soft PLC, and communication link simulation is used using GNS and tools, which solves the problem of the inability to simulate security characteristics in the existing technology, and realizes efficient vulnerability scanning and security measures verification, improving the authenticity and functionality of the simulation platform.

CN114779663BActive Publication Date: 2025-08-26SHANDONG ZHENGZHONG COMP NETWORK TECH CONSULTING
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210452627.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-27
Publication Date
2025-08-26
Estimated Expiration
2042-04-27

AI Technical Summary

Technical Problem

The existing technology cannot effectively simulate the safety characteristics and safety measures of industrial control systems, especially under the requirements of high real-time performance, which cannot simulate protocols such as Modbus and Profinet, resulting in the inability to verify the effectiveness of security protection measures of industrial control systems.

Method used

Lightweight virtualization technology is used to simulate the five-layer structure of industrial control systems, combine hardware PLC and soft PLC, simulate communication links using GNS, and perform data analysis and security attack simulation through Wireshark and scapy tools to achieve rapid deployment and vulnerability scanning.

Benefits of technology

It improves the authenticity and comprehensiveness of the simulation environment, can quickly deploy and analyze traffic per layer, provide vulnerability mining and security measures verification environment, and takes into account both hard real-time and soft real-time simulation, expanding the simulation scope.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114779663B_ABST
    Figure CN114779663B_ABST
Patent Text Reader

Abstract

This paper proposes a lightweight virtualization-based industrial control system security simulation method, which includes: using lightweight virtualization technology to simulate the five layers of an industrial control system; during the simulation process, lightweight virtualization technology is used to build the underlying environment for each layer, and the simulation is rapidly deployed in batches. The direct traffic at each layer is captured and analyzed. Relying on this secure simulation environment, the present invention verifies the effectiveness of security measures such as data encryption, identity authentication, and access control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control system security, and in particular relates to an industrial control system security simulation method based on lightweight virtualization. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] With the deep integration of informatization and industrialization, industrial control systems no longer operate only in the original closed environment, but need to be linked with the upper-level decision-making system.

[0004] Once industrial control systems are connected to the internet, the cost of hacker attacks is significantly reduced, leaving them vulnerable to traditional computer security threats such as Trojans, message theft, message tampering, and replay attacks. While some protective measures exist, their effectiveness cannot be verified in real-world environments, potentially leading to system failure or downtime.

[0005] In the existing technology, cloud-based soft PLC system architecture has been studied, but only a set of industrial control system simulation environments has been built. It is not suitable for industrial control systems with high real-time requirements. OPC-UA is used to complete communication, and more attention is paid to the simulation of industrial control system functions. Security simulation is not considered for the time being. Therefore, it is impossible to simulate protocols such as Modbus and Profinet used in real environments, nor is it possible to simulate the effectiveness of security features and security measures. Summary of the Invention

[0006] To overcome the deficiencies of the above-mentioned prior art, the present invention provides an industrial control system security simulation method based on lightweight virtualization, which can not only be applied to industrial control system vulnerability scanning and mining, but also can be applied to the verification of the effectiveness of industrial control security products.

[0007] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions:

[0008] In a first aspect, a lightweight virtualization-based industrial control system security simulation method is disclosed, including:

[0009] Use lightweight virtualization technology to simulate the five layers of industrial control systems;

[0010] During the simulation process, each layer uses lightweight virtualization technology to build the underlying environment and conducts rapid batch deployment. The direct traffic at each layer is captured and analyzed.

[0011] As a further technical solution, lightweight virtualization technology is used to simulate the five layers of the industrial control system, specifically:

[0012] At the field control layer and process monitoring layer, a combination of hardware PLC and soft PLC is used to simulate hard real-time and soft real-time at the same time;

[0013] Lightweight virtualization technology is used at the production management layer and enterprise resource layer to quickly simulate production management and enterprise resource management systems;

[0014] At the field device layer, lightweight virtualization technology is used to simulate device execution and data collection.

[0015] As a further technical solution, during the communication between the process monitoring layer and the field control layer, both communicating parties are deployed in a lightweight virtualized container to simulate the Modbus Slave and Master ends of the communication.

[0016] As a further technical solution, the communication network between the process monitoring layer and the field control layer does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links of different nodes in the industrial control system.

[0017] As a further technical solution, GNS is used to simulate the communication links of different nodes in the industrial control system. Afterwards, Wireshark is used to capture the communication data packets and analyze the data flow of the data packets.

[0018] As a further technical solution, GNS is used to simulate the communication links of different nodes in the industrial control system, and the scapy tool is used to simulate security attacks on the industrial control system.

[0019] In a second aspect, an industrial control system is disclosed, comprising a field device layer, a field control layer, a process monitoring layer, a production management layer, and an enterprise resource layer;

[0020] Use lightweight virtualization technology to simulate the five layers of industrial control systems;

[0021] During the simulation process, each layer uses lightweight virtualization technology to build the underlying environment and conducts rapid batch deployment. The direct traffic at each layer is used for capture and analysis.

[0022] As a further technical solution, a combination of hardware PLC and soft PLC is used at the field control layer and process monitoring layer to simulate hard real-time and soft real-time at the same time;

[0023] Lightweight virtualization technology is used at the production management layer and enterprise resource layer to quickly simulate production management and enterprise resource management systems;

[0024] At the field device layer, lightweight virtualization technology is used to simulate device execution and data collection.

[0025] As a further technical solution, during the communication between the process monitoring layer and the field control layer, both communicating parties are deployed in a lightweight virtualized container to simulate the Modbus Slave and Master ends of the communication.

[0026] As a further technical solution, the communication network between the process monitoring layer and the field control layer does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links of different nodes in the industrial control system.

[0027] One or more of the above technical solutions have the following beneficial effects:

[0028] The present invention adopts a method that combines hardware PLC and soft PLC to improve the comprehensiveness and authenticity of system verification, and the simulation environment is closer to the real situation. In addition, through the lightweight virtualization container in the simulation environment, the production management layer and enterprise resource layer simulation system can be quickly deployed, which can not only be used for industrial control system vulnerability scanning and mining, but also can be used to verify the effectiveness of industrial control security products.

[0029] The present invention expands the simulation scope and uses lightweight virtualization technology to simulate the five layers of the industrial control system. During the simulation process, each layer uses lightweight virtualization technology to quickly build the underlying environment and can achieve rapid batch deployment; the direct traffic of each layer can be easily captured and analyzed.

[0030] The present invention not only completes soft real-time simulation, but also takes into account hard real-time simulation and other simulations that are close to actual application scenarios.

[0031] In addition to completing functional simulation, the present invention focuses on simulating the security of industrial control systems, providing an environment for vulnerability mining and vulnerability scanning on the one hand, and a penetration testing environment on the other hand, and provides an environment for verifying the effectiveness of security measures.

[0032] The industrial control system security simulation platform proposed in the present invention can be used for one-click rapid deployment of lightweight virtualization containers, and can realize the visualization presentation function of industrial control system traffic, which is convenient for analysis and presentation.

[0033] Advantages of additional aspects of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0035] Figure 1 This is a system diagram of an embodiment of the present invention;

[0036] Figure 2 This is a schematic diagram of a simulation node according to an embodiment of the present invention;

[0037] Figure 3 Schematic diagram of the overall simulation node of an embodiment of the present invention. DETAILED DESCRIPTION

[0038] It should be noted that the following detailed descriptions are exemplary and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present invention belongs.

[0039] It should be noted that the terms used herein are for describing particular embodiments only and are not intended to limit the exemplary embodiments according to the present invention.

[0040] In the absence of conflict, the embodiments of the present invention and the features thereof may be combined with each other.

[0041] Example 1

[0042] See attached Figure 2-3 As shown, this embodiment discloses an industrial control system security simulation method based on lightweight virtualization, specifically:

[0043] Simulation is proposed for each layer: field equipment layer, field control layer, process monitoring layer, production management layer, and enterprise resource layer.

[0044] At the field control and process monitoring layers, a combination of hardware and software PLCs is employed to enhance the authenticity of industrial control system verification, making the simulation platform closer to reality while simulating both hard and soft real-time. Lightweight virtualization technology is employed at the production management and enterprise resource layers to enable rapid simulation of production management and enterprise resource management systems. Lightweight virtualization technology inherently possesses simulation capabilities, enabling not only rapid batch deployment but also service orchestration. At the field device layer, lightweight virtualization technology is also used to simulate device execution and data collection.

[0045] During the communication between the process monitoring layer and the field control layer, the present invention also deploys both communicating parties in a lightweight virtualization container, and uses pymodbus to simulate the Modbus Slave and Master ends of the communication; the intermediate communication network does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links of different nodes in the industrial control system, which facilitates the subsequent capture of data traffic.

[0046] The present invention uses GNS to simulate the communication links of different nodes in the industrial control system. On this basis, Wireshark can be used to capture communication data packets and analyze the data flow of the data packets. With the help of tools such as Scapy, security attacks on industrial control systems can be simulated. In addition, the effectiveness of security measures can be verified by relying on this security simulation environment.

[0047] During the communication between the process monitoring layer and the field control layer, the present invention also deploys both communicating parties in a lightweight virtualization container, and uses pymodbus to simulate the Modbus Slave and Master ends of the communication; the intermediate communication network does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links of different nodes in the industrial control system, which facilitates the subsequent capture of data traffic.

[0048] The present invention uses GNS to simulate the communication links of different nodes in the industrial control system. Relying on the network simulation environment, Wireshark can be used to capture communication data packets and analyze the data flow of the data packets. Relying on the industrial control system security simulation environment, tools such as Scapy can be used to simulate security attacks on the industrial control system. In addition, the security simulation environment can also be used to verify the effectiveness of security measures such as data encryption, identity authentication, and access control.

[0049] This invention expands the simulation scope and uses lightweight virtualization technology to simulate the five layers of the industrial control system. During the simulation process, each layer uses lightweight virtualization technology to quickly build the underlying environment and can achieve rapid batch deployment; the direct traffic of each layer can be easily captured and analyzed;

[0050] The present invention not only completes soft real-time simulation, but also takes into account hard real-time simulation that is close to actual application scenarios;

[0051] In addition to completing functional simulation, the present invention focuses on simulating the security of industrial control systems, providing an environment for vulnerability mining and vulnerability scanning on the one hand, and a penetration testing environment on the other hand, and an environment for verifying the effectiveness of security measures;

[0052] The industrial control system security simulation platform proposed in the present invention can be used for one-click rapid deployment of lightweight virtualization containers, and can realize the visualization presentation function of industrial control system traffic, which is convenient for analysis and presentation.

[0053] Example 2

[0054] See attached Figure 1 As shown, the purpose of this embodiment is to provide an industrial control system, which includes five layers from bottom to top: field device layer, field control layer, process monitoring layer, production management layer, and enterprise resource layer.

[0055] Use lightweight virtualization technology to simulate the five layers of industrial control systems;

[0056] During the simulation process, each layer uses lightweight virtualization technology to build the underlying environment and conducts rapid batch deployment. The direct traffic at each layer is used for capture and analysis.

[0057] At the field control layer and process monitoring layer, a combination of hardware PLC and soft PLC is used to simulate hard real-time and soft real-time at the same time;

[0058] Lightweight virtualization technology is used at the production management layer and enterprise resource layer to quickly simulate production management and enterprise resource management systems;

[0059] At the field device layer, lightweight virtualization technology is used to simulate device execution and data collection.

[0060] This invention combines hardware PLC and soft PLC at the field control and process monitoring layers, improving the authenticity of industrial control system verification and making the simulation platform closer to reality, simulating both hard and soft real-time. Lightweight virtualization technology is used at the production management and enterprise resource layers to enable rapid simulation of production management and enterprise resource management systems. Lightweight virtualization technology inherently possesses simulation capabilities, enabling not only rapid batch deployment but also service orchestration.

[0061] During the communication between the process monitoring layer and the field control layer, both communicating parties are deployed in a lightweight virtualized container to simulate the Modbus Slave and Master ends of the communication.

[0062] The communication network between the process monitoring layer and the field control layer does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links of different nodes in the industrial control system.

[0063] The present invention focuses more on the simulation of industrial control system functions in its research on cloud-based soft PLC system architecture, but has not yet considered the issue of security simulation, and is unable to simulate protocols such as Modbus and Profinet used in real environments. The present invention uses GNS to simulate the communication links of different nodes in the industrial control system. Relying on the network simulation environment, Wireshark can be used to capture communication data packets and analyze the data flow of data packets; relying on the industrial control system security simulation environment, tools such as scapy can be used to simulate security attacks on industrial control systems; in addition, the security simulation environment can also be used to verify the effectiveness of security measures, such as data encryption, identity authentication, access control, etc.

[0064] Although the above describes the specific embodiments of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without any creative work are still within the scope of protection of the present invention.

Claims

1. The industrial control system security simulation method based on lightweight virtualization is characterized by: include: Use lightweight virtualization technology to simulate the five layers of industrial control systems; During the simulation process, each layer uses lightweight virtualization technology to build the underlying environment and conducts rapid batch deployment. The direct traffic at each layer is captured and analyzed. Lightweight virtualization technology is used to simulate the five layers of industrial control systems, specifically: At the field control layer and process monitoring layer, a combination of hardware PLC and soft PLC is used to simulate hard real-time and soft real-time at the same time; Lightweight virtualization technology is used at the production management layer and enterprise resource layer to quickly simulate production management and enterprise resource management systems; The field device layer simulates device execution and data collection through lightweight virtualization technology; The communication network between the process monitoring layer and the field control layer does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links between different nodes in the industrial control system; GNS is used to simulate the communication links of different nodes in the industrial control system, and the scapy tool is used to simulate security attacks on the industrial control system.

2. The industrial control system security simulation method based on lightweight virtualization according to claim 1 is characterized in that: During the communication between the process monitoring layer and the field control layer, both communicating parties are deployed in a lightweight virtualized container to simulate the Modbus Slave and Master ends of the communication.

3. The industrial control system security simulation method based on lightweight virtualization according to claim 1 is characterized in that: GNS is used to simulate the communication links of different nodes in the industrial control system. Afterwards, Wireshark is used to capture the communication data packets and analyze the data flow of the data packets.

4. An industrial control system, characterized in that: The industrial control system includes a field device layer, a field control layer, a process monitoring layer, a production management layer, and an enterprise resource layer; Use lightweight virtualization technology to simulate the five layers of industrial control systems; During the simulation process, each layer uses lightweight virtualization technology to build the underlying environment and conducts rapid batch deployment. The direct traffic at each layer is captured and analyzed. Lightweight virtualization technology is used to simulate the five layers of industrial control systems, specifically: At the field control layer and process monitoring layer, a combination of hardware PLC and soft PLC is used to simulate hard real-time and soft real-time at the same time; Lightweight virtualization technology is used at the production management layer and enterprise resource layer to quickly simulate production management and enterprise resource management systems; The field device layer simulates device execution and data collection through lightweight virtualization technology; The communication network between the process monitoring layer and the field control layer does not use the network provided by the lightweight virtualization container, but uses GNS to simulate the communication links between different nodes in the industrial control system; GNS is used to simulate the communication links of different nodes in the industrial control system, and the scapy tool is used to simulate security attacks on the industrial control system.

5. An industrial control system as claimed in claim 4, characterized in that During the communication between the process monitoring layer and the field control layer, both communicating parties are deployed in a lightweight virtualized container to simulate the Modbus Slave and Master ends of the communication.

Citation Information

Patent Citations

  • An SDN-based industrial control system dynamic defense method and device

    CN109862045A

  • Industrial control system security defense method and device based on dynamic diversification

    CN110430209A