Attack detection method, system, terminal device, and storage medium

By introducing loop probes into industrial control systems, calculating residual parameters, and performing similarity checks, the problems of missed and false alarms caused by changes in operating conditions and external disturbances are solved, the accuracy of attack detection is improved, and the security protection requirements of industrial control systems are met.

CN115032895BActive Publication Date: 2025-11-07深圳市三旺通信股份有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210608928.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-31
Publication Date
2025-11-07
Estimated Expiration
2042-05-31

AI Technical Summary

Technical Problem

Existing attack detection methods for industrial control systems are prone to false alarms and missed alarms under changing operating conditions and external disturbances, making it difficult to accurately detect whether an attack has occurred and failing to meet security protection requirements.

Method used

By introducing loop probes into industrial control systems, disturbance parameters and residual parameters of real-time sensing signals are received and calculated. Combined with similarity checks, it is determined whether data packets have been attacked or tampered with. If no attack has occurred, a similarity check command is sent for further detection.

Benefits of technology

It effectively reduces the false negative and false positive rates of attack detection, improves the accuracy of attack detection, and meets the security protection requirements of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115032895B_ABST
    Figure CN115032895B_ABST
Patent Text Reader

Abstract

The application discloses an attack detection method, system, terminal equipment and storage medium. The attack detection method comprises the following steps: receiving a data packet sent by a loop probe, wherein the data packet comprises a disturbance parameter, a preset signal parameter and a real-time sensing signal; calculating a residual parameter based on the preset signal parameter and the real-time sensing signal; judging whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if the data packet is not attacked and tampered, sending a similarity verification instruction to the loop probe, so that the loop probe performs attack detection on a real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe. The application solves the problems of attack detection false negatives and false positives, and improves the accuracy of attack detection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of security protection, and in particular to an attack detection method and system, a terminal device, and a storage medium. BACKGROUND

[0002] Industrial control systems are an important part of national critical infrastructure, but in the use of industrial control systems, they are often attacked, causing great impact on national industry and economic losses.

[0003] The existing method for detecting false data injection is mainly based on threshold detection of Kalman filtering. In the case of no strong external disturbance in the industrial process control system and constant working conditions, the above method has good effect in attack detection in the industrial process. However, in actual industrial process production, the working conditions are not constant, which leads to false positives of the above attack detection method based on Kalman filtering due to changes in working conditions. In addition, there are also external disturbances in industrial process control systems. The above attack detection method based on Kalman filtering is difficult to distinguish between large external disturbances and actual attacks, and external disturbances are also subject to attacks. Therefore, disturbances and changes in working conditions result in high false positive and false negative rates of the existing attack detection method, which limits its practical application in industrial process control system attack monitoring.

[0004] Therefore, how to accurately detect whether an industrial control system has been attacked based on changes in working conditions, and how to avoid attack false positives and false negatives caused by changes in working conditions and disturbances, so as to better meet the security protection requirements of industrial control systems, is a difficult problem that needs to be solved in the field of industrial production. SUMMARY

[0005] The main purpose of the present application is to provide an attack detection method, system, terminal device, and storage medium, which aims to solve the problem of attack detection false positives and false negatives and improve the accuracy of attack detection.

[0006] To achieve the above purpose, the present application provides an attack detection method, which is applied to a controller, the controller interacts with a loop probe, and the attack detection method comprises:

[0007] receiving a data packet sent by the loop probe, the data packet containing a disturbance parameter, a preset signal parameter, and a real-time sensing signal, and calculating a residual parameter based on the preset signal parameter and the real-time sensing signal;

[0008] Based on the residual parameter and the disturbance parameter, it is judged whether the data packet has been attacked and tampered with;

[0009] If the data packet is not tampered by the attack, a similarity check instruction is sent to the loop probe for the loop probe to detect the attack on the real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is converted by the loop probe.

[0010] Optionally, the step of determining whether the data packet is tampered by the attack based on the residual parameter and the disturbance parameter comprises:

[0011] If the residual parameter is equal to the disturbance parameter, it indicates that the data packet is not tampered by the attack.

[0012] If the difference between the residual parameter and the disturbance parameter exceeds a preset threshold, it indicates that the data packet is tampered by the attack.

[0013] Optionally, the step after determining whether the data packet is tampered by the attack based on the residual parameter and the disturbance parameter comprises:

[0014] If the data packet is tampered by the attack, a first attack alarm information is triggered.

[0015] The application further provides an attack detection method, which is applied to a loop probe, the loop probe interacts with a controller, and the attack detection method comprises the following steps:

[0016] Obtaining a pre-processed real-time sensing signal and a corresponding real-time control signal;

[0017] Calculating the real-time sensing signal and a preset signal parameter to obtain a disturbance parameter;

[0018] Sending a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and determines whether the data packet is tampered by the attack based on the residual parameter and the disturbance parameter;

[0019] If the similarity check instruction sent by the controller is received, the attack on the real-time control signal is detected based on the real-time sensing signal.

[0020] Optionally, the loop probe further interacts with a sensor, and the step of obtaining the pre-processed real-time control signal and the real-time sensing signal comprises:

[0021] Obtaining a stable sensing signal sent by the sensor and a stable control signal sent by the controller;

[0022] Converting the stable control signal and the stable sensing signal to obtain the real-time control signal and the real-time sensing signal correspondingly.

[0023] Optionally, the step of detecting attack on the real-time control signal based on the real-time sensing signal comprises:

[0024] calculating the real-time sensing signal and a preset reference value to obtain an error value;

[0025] calculating based on the error value and a preset control parameter to obtain an estimated control output;

[0026] checking whether the real-time control signal is similar to the estimated control output;

[0027] if not, it indicates that the attack tampering is suffered, and a second attack alarm information is triggered;

[0028] if yes, it indicates that the attack tampering is not suffered, and a step of converting the smooth control signal and the smooth sensing signal is executed to obtain the real-time control signal and the real-time sensing signal.

[0029] Optionally, the step of calculating the real-time sensing signal and a preset signal parameter to obtain a disturbance parameter comprises:

[0030] identifying a controlled object model based on the smooth control signal and the smooth sensing signal;

[0031] determining the preset signal parameter based on the controlled object model.

[0032] The embodiments of the present application also propose a detection system, and the false negative detection system comprises: a controller, a loop probe;

[0033] The controller is configured to receive a data packet containing a disturbance parameter, a preset signal parameter and a real-time sensing signal sent by the loop probe, and calculate a residual parameter based on the preset signal parameter and the real-time sensing signal; determine whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if the data packet is not attacked and tampered, send a similarity checking instruction to the loop probe, so that the loop probe detects attack on a real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe;

[0034] The loop probe is used to acquire a pre-processed real-time sensing signal and a corresponding real-time control signal; a disturbance parameter is calculated from the real-time sensing signal and a preset signal parameter; a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal is sent to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and judges whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if a similarity verification instruction sent by the controller is received, the real-time control signal is detected based on the real-time sensing signal.

[0035] The application further provides a terminal device, which comprises a memory, a processor, and an attack detection program stored in the memory and executable on the processor. When the attack detection program is executed by the processor, the steps of the attack detection method are implemented.

[0036] The application further provides a computer readable storage medium, which stores an attack detection program. When the attack detection program is executed by a processor, the steps of the attack detection method are implemented.

[0037] The attack detection method, system, terminal device and storage medium provided by the application can receive the data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal sent by the loop probe, calculate a residual parameter based on the preset signal parameter and the real-time sensing signal, judge whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter, and send a similarity verification instruction to the loop probe if the data packet is not attacked and tampered, so that the loop probe detects the real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is converted by the loop probe.

[0038] By adding a loop probe in the industrial control system, considering the case that the real-time sensing signal and the real-time control signal of the transmitted data are attacked at the same time, and adding a similarity verification in the loop probe, the false negative and false positive problems of attack detection can be solved, and the accuracy of attack detection can be improved. Based on the application, a detection system based on the loop probe is constructed from the problem of external disturbance existing in the industrial control system in the real world, the effectiveness of the attack detection method provided by the application is verified on the detection system, and finally the attack false negative rate and false alarm rate detected by the method of the application are obviously reduced. BRIEF DESCRIPTION OF DRAWINGS

[0039] Figure 1 It is a functional module schematic diagram of the terminal device to which the attack detection device of the application belongs;

[0040] Figure 2 Flowchart of the first embodiment of the attack detection method of the present application;

[0041] Figure 3 Structure diagram of the detection system involved in the attack detection method of the present application;

[0042] Figure 4 Application flowchart of the detection system involved in the attack detection method of the present application;

[0043] Figure 5 Flowchart of the attack detection of the attack detection method of the present application;

[0044] Figure 6 Effect diagram of the disturbance residual detection of the attack detection method of the present application under the non-attack state of the loop;

[0045] Figure 7 Effect diagram of the disturbance residual detection of the attack detection method of the present application under the same attack on the loop output and the detected disturbance data;

[0046] Figure 8 Effect diagram of the disturbance residual detection of the attack detection method of the present application under different attacks on the loop output and the detected disturbance data;

[0047] Figure 9 Flowchart of the second embodiment of the attack detection method of the present application;

[0048] Figure 10 Flowchart of the signal data preprocessing of the attack detection method of the present application;

[0049] Figure 11 Flowchart of the similarity test of the attack detection method of the present application;

[0050] Figure 12 Effect diagram of the similarity test of the attack detection method of the present application under the same attack on the loop output and the detected disturbance data;

[0051] Figure 13 Result diagram of the similarity calculation of the attack detection method of the present application under the same attack on the loop output and the detected disturbance data;

[0052] Figure 14 Effect diagram of the similarity test of the attack detection method of the present application under the non-attack state of the loop.

[0053] The implementation, functional features and advantages of the present application will be further explained with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0054] It should be understood that the specific embodiments described herein merely set forth preferred embodiments of the present application and that structure of the application can be used to advantage in any method in accordance with the application.

[0055] The main solution of the embodiment of the application is that a data packet containing a disturbance parameter, a preset signal parameter and a real-time sensing signal is received, and a residual parameter is calculated based on the preset signal parameter and the real-time sensing signal; whether the data packet is attacked and tampered is judged based on the residual parameter and the disturbance parameter; if not, a similarity verification instruction is sent to the loop probe for attack detection of a real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe. By adding a loop probe in the industrial control system, considering the case that the real-time sensing signal and the real-time control signal of the transmitted data are attacked at the same time, and adding similarity verification in the loop probe, the attack detection false negative and false positive problems can be solved, and the accuracy of attack detection is improved. Based on the scheme of the application, starting from the problem of external disturbance existing in the industrial control system in the real world, a detection system based on the loop probe is constructed, and the effectiveness of the attack detection method proposed in the application is verified on the detection system. Finally, the attack false negative rate and false alarm rate detected by the method of the application are obviously reduced.

[0056] The embodiment of the application considers that the existing method for detecting false data injection is mainly based on Kalman filter threshold detection. In the case that the working condition is unchanged and there is no strong external disturbance in the industrial process control system, the attack detection method in the industrial process has good effect. However, in actual industrial process production, the working condition is not constant, which leads to the attack false positive of the above-mentioned attack detection method based on Kalman filter due to the change of working condition. In addition, there is also external disturbance in the industrial process control system, and the above-mentioned attack detection method based on Kalman filter is difficult to distinguish the external disturbance with large intensity from the actual attack, and the external disturbance will also be attacked. Therefore, the disturbance and the change of working condition make the false negative rate and the false positive rate of the existing attack detection method high, which limits the actual application in the attack monitoring of the industrial process control system.

[0057] Therefore, how to accurately detect whether the industrial control system is attacked based on the change of working condition, and how to avoid the attack false negative and false positive caused by the change of working condition and disturbance to meet the safety protection requirements of the industrial control system to a greater extent are difficult problems to be solved in the field of industrial production at present.

[0058] Specifically, referring to Figure 1 , Figure 1Fig. 1 is a schematic diagram of a functional module of a terminal device to which the attack detection device of the present application belongs. The attack detection device can be a device independent of the terminal device and capable of creating a system and detecting an attack, which can be carried on the terminal device in the form of hardware or software. The terminal device can be a smart mobile terminal such as a mobile phone or a tablet computer, or a fixed terminal device or a server with a data processing function.

[0059] In the present embodiment, the terminal device to which the attack detection device belongs at least includes an output module 110, a processor 120, a memory 130, and a communication module 140.

[0060] The memory 130 stores an operating system and an attack detection program. The attack detection device can send, to the loop probe, a data packet containing a disturbance parameter, a preset signal parameter, and a real-time sensing signal, calculate a residual parameter, and send, to the loop probe, a similarity verification instruction if the data packet is not tampered with. The loop probe can obtain a pre-processed real-time control signal and a real-time sensing signal, calculate a disturbance parameter based on the real-time sensing signal and the preset signal parameter, and send, to the controller, a data packet containing the disturbance parameter, the preset signal parameter, and the real-time sensing signal. The attack detection device can receive a similarity verification instruction sent by the controller, and the information is stored in the memory 130. The output module 110 can be a display screen. The communication module 140 can include a WIFI module, a mobile communication module, and a Bluetooth module, and communicate with external devices or servers through the communication module 140.

[0061] When the attack detection program in the memory 130 is executed by the processor, the following steps are implemented:

[0062] receiving a data packet containing a disturbance parameter, a preset signal parameter, and a real-time sensing signal sent by the loop probe, and calculating a residual parameter based on the preset signal parameter and the real-time sensing signal;

[0063] judging whether the data packet is tampered with based on the residual parameter and the disturbance parameter;

[0064] if the data packet is not tampered with, sending a similarity verification instruction to the loop probe, so that the loop probe performs attack detection on a real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion by the loop probe.

[0065] Further, when the attack detection program in the memory 130 is executed by the processor, the following steps are implemented:

[0066] if the residual parameter is equal to the disturbance parameter, it indicates that the data packet is not tampered with.

[0067] If the difference between the residual parameter and the disturbance parameter exceeds a preset threshold, it indicates that the data packet is subjected to attack tampering.

[0068] Further, the attack detection program in the memory 130, when executed by the processor, also implements the following steps:

[0069] If subjected to attack tampering, a first attack alarm information is triggered.

[0070] Further, the attack detection program in the memory 130, when executed by the processor, also implements the following steps:

[0071] Obtaining the smooth sensor signal sent by the sensor and the smooth control signal sent by the controller;

[0072] Converting the smooth control signal and the smooth sensor signal to obtain the real-time control signal and the real-time sensor signal.

[0073] Further, the attack detection program in the memory 130, when executed by the processor, also implements the following steps:

[0074] Calculating the real-time sensor signal and the preset reference value to obtain an error value;

[0075] Based on the error value and a preset control parameter, an estimated control output is obtained;

[0076] Verifying whether the real-time control signal is similar to the estimated control output;

[0077] If not, it indicates that it is subjected to attack tampering, and a second attack alarm information is triggered;

[0078] If yes, it indicates that it is not subjected to attack tampering, and the step of converting the smooth control signal and the smooth sensor signal to obtain the real-time control signal and the real-time sensor signal is executed.

[0079] Further, the attack detection program in the memory 130, when executed by the processor, also implements the following steps:

[0080] Identifying a controlled object model based on the smooth control signal and the smooth sensor signal;

[0081] Determining the preset signal parameter based on the controlled object model.

[0082] The embodiment is based on the above scheme, specifically by receiving the data packet sent by the loop probe, the data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal, and calculating the residual parameter based on the preset signal parameter and the real-time sensing signal; based on the residual parameter and the disturbance parameter, it is judged whether the data packet is attacked and tampered; if not, send a similarity verification instruction to the loop probe for attack detection of the real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe. Based on the scheme, starting from the problem of external disturbance existing in the industrial control system in the real world, a detection system based on the loop probe is constructed, and the effectiveness of the attack detection method proposed in the application is verified on the detection system. Finally, the attack false alarm rate and false alarm rate detected by the method are significantly reduced.

[0083] Based on the above terminal device architecture but not limited to the above architecture, the method embodiment of the application is proposed.

[0084] It should be noted that the attack in the industrial process generally acts on the closed-loop control loop of the control system, thereby affecting the entire industrial production process. Among them, the false data injection (FDI) attack is the most common form of attack.

[0085] The existing method for detecting false data injection is mainly based on threshold detection based on Kalman filtering. In the case of unchanged working condition and no strong external disturbance in the industrial process control system, the above method has good effect in attack detection in the industrial process. However, in actual industrial process production, the working condition is not constant, which leads to the fact that the above attack detection method based on Kalman filtering is prone to attack false alarm due to working condition change. In addition, there are also external disturbances in the industrial process control system, and the above attack detection method based on Kalman filtering is difficult to distinguish between strong external disturbances and actual attacks, and external disturbances are also subject to attacks. Therefore, the disturbance and the working condition change make the false alarm rate and the false alarm rate of the existing attack detection method high, which limits the actual application in the attack monitoring of the industrial process control system.

[0086] Therefore, how to accurately detect whether the industrial control system is attacked based on the working condition change, and how to avoid attack false alarm and false alarm caused by working condition change and disturbance, so as to meet the safety protection requirements of the industrial control system to a greater extent, is a difficult problem that needs to be solved in the field of industrial production at present.

[0087] Reference Figure 2 , Figure 2A flowchart of a first embodiment of an attack detection method of the present application. The attack detection method is applied to a controller, the controller interacts with a loop probe, and the attack detection method comprises the following steps:

[0088] In step S210, a data packet containing a disturbance parameter, a preset signal parameter and a real-time sensing signal is received from the loop probe, and a residual parameter is calculated based on the preset signal parameter and the real-time sensing signal;

[0089] Specifically, in the process of sending the data packet to the controller by the loop probe, if the industrial process control loop is attacked, the data packet will be attacked and tampered with, so that the real-time sensing signal y(k) and / or the disturbance parameter d(k) in the data packet will change. When the controller receives the data packet, the residual parameter z(k) is calculated according to the preset signal parameter y m (k) and the disturbance parameter d(k) in the data packet; the controller receives the data packet containing the disturbance parameter d(k), the preset signal parameter y m (k) and the real-time sensing signal y(k) sent by the loop probe, and performs comparison operation based on the preset signal parameter y m (k) and the real-time sensing signal y(k) under the steady operation condition of the industrial process control loop to obtain the residual parameter z(k), wherein the real-time sensing signal is converted by the controller from the loop probe in real time. The specific steps of calculating the residual parameter z(k) can be as follows:

[0090] Firstly, the controller converts the model into G m (z) through the pre-stored controlled object model G m (s) parameter of the loop probe, and converts the controller output time sequence u(k) into u(z), wherein the controlled object model G m (s) is obtained by offline identification of the steady control signal us and the steady sensing signal ys in the loop probe;

[0091] Then, the controller output u(z) and the controlled object model Gm(z) calculate the model output:

[0092] Y m (z)=u(z)*G m (z)

[0093] Then, y m (z) is converted into time sequence y m (k);

[0094] Finally, the residual parameter z(k) is calculated:

[0095] z(k)=y a (k)-y m (k)

[0096] Step S220, judging whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter;

[0097] Specifically, then the residual parameter z(k) is compared with the disturbance parameter d(k), to judge whether the difference between the real-time sensing signal and the preset signal parameter is caused by the disturbance due to the working condition change or caused by the attack on the industrial process control loop, while considering that the disturbance parameter is also attacked and tampered, to avoid attack false negatives.

[0098] For example, the data packet containing the preset signal parameter y m (k), the disturbance parameter d(k) and the real-time sensing signal y(k) sent by the loop probe is received by the controller, considering that the real-time sensing signal y(k) and / or the disturbance parameter d(k) may be subjected to a false data injection attack a(k) in this process, the data arriving at the controller / attack detector is recorded as d a (k) and y a (k), there are three cases:

[0099] The first case: neither d(k) nor y(k) is attacked, at this time d a (k)=d(k), y a (k)=y(k);

[0100] The second case: d(k) and y(k) are subjected to the same attack, at this time d a (k)=d(k)+a(k), y a (k)=y(k)+a(k);

[0101] The third case: d(k) and y(k) are subjected to different attacks, at this time d a (k)=d(k)+a1(k), d a (k)=d(k)+a2(k), a1(k)≠a2(k);

[0102] Then the residual parameter z(k) is compared with d a (k), to judge whether the difference between the real-time sensing signal and the preset signal parameter is caused by the disturbance due to the working condition change or caused by the attack on the industrial process control loop, while considering that the disturbance parameter is also attacked and tampered, to avoid attack false negatives.

[0103] Step S230, if not attacked and tampered, a similarity verification instruction is sent to the loop probe for the loop probe to perform attack detection on the real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion by the loop probe.

[0104] Specifically, if the controller detects that the system is not attacked and tampered, the similarity instruction is sent to the loop probe for the loop probe to perform similarity test on the real-time control signal u(k) based on the real-time sensing signal y(k) to perform secondary attack detection. Wherein, the real-time control signal is relatively corresponding to the real-time sensing signal. As an implementation manner, the real-time sensing signal y(k) and the real-time control signal u(k) are obtained by the loop probe at the same time; as another implementation manner, the real-time sensing signal y(k) and the real-time control signal u(k) are obtained by the loop probe in the actual situation or in the order set by the user. The embodiment takes the implementation manner that the loop probe converts the real-time sensing signal y(k) and the real-time control signal u(k) at the same time.

[0105] Reference Figure 3 , Figure 3 is the structure principle diagram of the detection system involved in the attack detection method of the application. The hardware structure of the detection system is specifically taken Figure 3 as an example, the control room includes a controller / attack detector, and the industrial field includes an actuator, a controlled object, a disturbance channel, a sensor and a loop probe, and the control room and the industrial field transmit data through a communication network. The overall data flow of the detection system is shown in Figure 3 .

[0106] Firstly, a step disturbance signal is added to the disturbance channel in the detection system, and a(k) (step attack signal) is added to the communication network in the system; then, the disturbance signal acts on the system after passing through the disturbance channel, and white noise is added to the system; then, the sensor converts y(s) (stationary sensing signal) and u(s) (stationary control signal) to obtain y(k) (real-time sensing signal) and u(k) (real-time control signal) in real time and sends them to the loop probe; after receiving y(k) and u(k), the loop probe calculates d(k) (disturbance parameter) according to the preset signal parameter and the real-time sensing signal, and sends d(k) and y(k) to the controller / attack detector; since the transmission data may be attacked by a(k) and tampered during transmission through the communication network, d(k) and y(k) become d a (k) and y a (k) when they arrive at the controller / attack detector; then, the controller / attack detector sends the output u1(k) of the controller to the actuator; then, the actuator converts u1(k) to u1(s) to control the controlled object; finally, the sensor converts u1(s) and y1(s) again in real time and sends them as new y(k) and u(k), thus forming a loop.

[0107] Where the control signal u(s) and the sensor output signal y(s) conform to the 4-20 mA standard, the system uses a classic PID controller, the proportional coefficient Kc=2.4, the integral time constant Ti=8.8, and the derivative time constant Td=0, and the real transfer function model of the controlled object is

[0108]

[0109] The disturbance channel transfer function is

[0110]

[0111] The system sampling time Ts is set to 1 s, the reference value r(k) is set to 0, and the false data injection attack acts on the communication network between the industrial process field and the control room. In the system, a step disturbance signal with an amplitude of 1 is added at t=150 s, and a step attack signal is added at t=300 s, where the amplitude of a(k) is -1, the amplitude of a1(k) is -1, and the amplitude of a2(k) is -0.5. The disturbance signal acts on the system after passing through the disturbance channel, and the attack signal directly acts on the sensor signal y(k). In order to simulate the real scene, white noise is added in the system. The first threshold value d th of the disturbance residual judgment method in this example is set to 0.1, and if the difference exceeds the first threshold value, it is judged that the attack tampering is suffered; the second threshold value S th of the similarity test method is set to 0.8, and by calculating the cosine similarity S between the signals, if the cosine similarity S is lower than the second threshold value, the similarity test is not passed.

[0112] Reference Figure 4 , Figure 4 is the application flowchart of the detection system involved in the detection method of the present application. First, the loop probe collects historical input data u(s) and output data y(s) under normal operating conditions of the control loop; then a classic model identification method is used to estimate the controlled object model G m (s); the loop probe stores the G m (s) parameters and sends them to the controller, and the controller stores G m (s); then the loop probe converts u(s) and y(s) in real time, and the corresponding u(k) and y(k) are obtained; then the system model output y m (k) is calculated based on the microprocessor in the loop probe, and the disturbance parameter d(k)=y(k)-y m (k) is calculated; then the loop probe sends d(k) and y(k) to the controller, and the data reaching the controller is d a (k) and y a(k); the controller receives the transmission data and performs attack detection; it is judged whether the transmission data is attacked and tampered with, if yes, attack warning is performed, and step loop probe real-time conversion u(s) and y(s) is performed to form a loop; if not, similarity test is performed in the loop probe; if yes, it indicates that the system is not attacked and tampered with, and step loop probe real-time conversion u(s) and y(s) is performed to form a loop; if the test fails, attack warning is performed, and step loop probe real-time conversion u(s) and y(s) is performed to form a loop.

[0113] The embodiment realizes the above scheme, specifically, receives the data packet sent by the loop probe and containing the disturbance parameter, the preset signal parameter and the real-time sensing signal, and calculates the residual parameter based on the preset signal parameter and the real-time sensing signal; based on the residual parameter and the disturbance parameter, it is judged whether the data packet is attacked and tampered with; if not, a similarity test instruction is sent to the loop probe for attack detection on the real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe. By considering the case that the real-time sensing signal and the real-time control signal of the transmission data are attacked at the same time, and adding similarity test in the loop probe, the false negative and false positive problems of attack detection can be solved, and the accuracy of attack detection is improved.

[0114] Reference Figure 5 , Figure 5 The figure is a flowchart of the attack detection method of the application. Based on the above Figure 2 embodiment, step S220, based on the residual parameter and the disturbance parameter, the step of judging whether the data packet is attacked and tampered with includes:

[0115] Step S510, if the residual parameter is equal to the disturbance parameter, it indicates that the data packet is not attacked and tampered with;

[0116] Specifically, considering that the real-time sensing signal y(k) and / or the interference parameter d(k) may be subjected to a false data injection attack a(k), the data arriving at the controller / attack detector is recorded as d a (k) and y a (k), based on the residual parameter z(k) and the disturbance parameter d(k), if the residual parameter z(k) is equal to the disturbance parameter d(k), it indicates that the data packet is not attacked and tampered with. Wherein, not attacked and tampered with includes at least two cases.

[0117] The first case: d(k) and y(k) are not attacked, at this time d a (k) = d(k), y a (k) = y(k);

[0118] Thus, z(k) = ya(k) - y m (k) = y(k) - y m (k) = d(k) = da(k), at this time, it is judged that the system is not attacked and tampered with, and step S230 is performed.

[0119] In this embodiment, a step disturbance signal with an amplitude of 1 is added to the system at t = 150s, and a step attack signal is added at t = 300s, wherein the amplitude of a(k) is -1, the amplitude of a1(k) is -1, and the amplitude of a2(k) is -0.5. The disturbance signal acts on the system after passing through the disturbance channel, and the attack signal directly acts on the sensor signal y(k). In order to simulate the real scene, white noise is added to the system. In this example, the first preset threshold d th of the disturbance residual judgment method is 0.1.

[0120] Reference Figure 6 , Figure 6 is a disturbance residual detection effect diagram of the loop without attack in the attack detection method of the application. As shown in Figure 6 , the curve of the residual parameter z(k) and d a (k) is basically coincided, that is, the z-da curve shown in the figure is basically stable. At this time, it is judged that the system is not attacked and tampered with.

[0121] The second case: d(k) and y(k) are subjected to the same attack, at this time d a (k) = d(k) + a(k), y a (k) = y(k) + a(k);

[0122] Thus, z(k) = y a (k) - y m (k) = y(k) + a(k) - y m (k) = d(k) + a(k) = d a (k); at this time, the transmission data is attacked, but the controller judges that the system is not attacked and tampered with, that is, the judgment of the controller belongs to false judgment, and then step S230 is performed.

[0123] Reference Figure 7 , Figure 7 is a disturbance residual detection effect diagram of the loop output and the disturbance data detected in the attack detection method of the application under the same attack. As shown in Figure 7 , the curve of the residual parameter z(k) and d a (k) is basically coincided, that is, the z-da curve shown in the figure is basically stable. At this time, the transmission data is attacked, but the controller judges that the system is not attacked and tampered with, that is, the judgment of the controller belongs to false judgment.

[0124] Step S520, if the difference between the residual parameter and the disturbance parameter exceeds a preset threshold, it indicates that the data packet is attacked and tampered.

[0125] It should be noted that in the embodiment, the preset threshold range is a numerical range subjectively set by the user according to the actual situation of the industrial process control loop, which can be represented by a percentage of the peak value of the real-time sensing signal, which can be temperature, pressure, flow, liquid level or concentration, etc., without specific limitation here.

[0126] Specifically, d(k) and y(k) are subjected to different attacks, at which time d a (k) = d(k) + a1(k), d a (k) = d(k) + a2(k), a1(k) ≠ a2(k);

[0127] Then z(k) = y a (k) - y m (k) = y(k) + a1(k) - y m (k) = d(k) + a1(k), the difference between z(k) and d a (k) is z(k) - d a (k) = d(k) + a1(k) - (d(k) + a2(k)) = a1(k) - a2(k), if the difference a1(k) - a2(k) exceeds the preset threshold, then it is determined that the data packet is attacked and tampered, thereby determining that the industrial process control loop is attacked, and the first attack alarm information is generated.

[0128] Reference Figure 8 , Figure 8 is the loop output and the detected disturbance data of the attack detection method of the present application under different attack disturbance residual detection effect diagram. Here it is assumed that the preset threshold range d th, is 10% of the peak value of the real-time sensing signal y(k), the figure shows that after t = 300s, the difference between z(k) and d a (k) is about 0.5, the difference between the two exceeds the threshold d th = 0.1, indicating that the system is attacked, i.e. the z-da curve in the figure has a significant amplitude change. It is determined that the data packet is attacked and tampered, thereby determining that the industrial process control loop is attacked.

[0129] Further, step S220, after determining whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter, the step includes:

[0130] Step S530, if attacked and tampered, a first attack alarm information is triggered.

[0131] The controller triggers a first alarm information to remind the user to handle in time after determining that the industrial process control loop is attacked when the difference between the residual parameter and the disturbance parameter exceeds the preset threshold range; wherein the first alarm information includes sending an alarm information to the user terminal or performing a sound alarm, which is not limited here. It should be noted that according to the actual situation, the first attack alarm information in the present application can be the same as the second attack alarm information, or can be different alarm information. It should be noted that after the first attack alarm information is sent to the outside, or after the user handles the attack tampering of the data signal, the loop probe continues to perform the preprocessing of the real-time sensing signal and the real-time control signal, the controller receives the data packet sent by the loop probe and containing the disturbance parameter, the preset signal parameter and the real-time sensing signal, and judges whether the data packet is attacked and tampered, forming a loop.

[0132] In the embodiment, the data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal sent by the loop probe is received, and the residual parameter is calculated based on the preset signal parameter and the real-time sensing signal; if the residual parameter is equal to the disturbance parameter, it indicates that the data packet is not attacked and tampered; if the difference between the residual parameter and the disturbance parameter exceeds the preset threshold, it indicates that the data packet is attacked and tampered; if not attacked and tampered, a similarity check instruction is sent to the loop probe; if attacked and tampered, a first attack alarm information is triggered. By comparing the residual parameter with the disturbance parameter and the sensing signal to determine whether the data packet is attacked and tampered, whether the industrial process control loop is attacked and tampered is determined, which effectively avoids the attack false alarm caused by disturbance and improves the practicability of the attack detection method.

[0133] Reference Figure 9 , Figure 9 The flowchart of the second embodiment of the attack detection method of the present application is shown. The attack detection method is applied to a loop probe, the loop probe interacts with a controller, and the attack detection method comprises the following steps:

[0134] Step S910, obtaining the preprocessed real-time sensing signal and the corresponding real-time control signal;

[0135] Specifically, under normal operation of the industrial process control loop, the A / D converter installed in the detection loop probe of the industrial process control loop converts the smooth sensor signal y(s) sent by the sensor and the smooth control signal u(s) sent by the controller in real time to determine the initial content of the real-time sensor signal and the real-time control signal before the sensor transmits data to the controller. The real-time control signal corresponds to the real-time sensor signal. As an implementation manner, the real-time sensor signal y(k) and the real-time control signal u(k) are converted simultaneously by the loop probe; as another implementation manner, the real-time sensor signal y(k) and the real-time control signal u(k) are converted by the loop probe in a sequence according to actual conditions or user settings. The embodiment takes the implementation manner of simultaneously converting the real-time sensor signal y(k) and the real-time control signal u(k) by the loop probe.

[0136] For example, under normal operation of the industrial process control loop, the A / D converter in the detection loop probe converts the sensor signal y(s) sent by the sensor and the smooth control signal u(s) sent by the controller in real time to obtain the corresponding real-time sensor signal y(k) and real-time control signal u(k).

[0137] In step S920, the real-time sensor signal is calculated with the preset signal parameter to obtain the disturbance parameter.

[0138] Specifically, the detection loop probe compares the real-time sensor signal y(k) obtained by real-time conversion with the preset signal parameter under the smooth operation of the industrial process control loop to perform comparison operation, and takes the difference value obtained by operation as the disturbance parameter corresponding to the disturbance caused by the change of working condition. For example, the output of the system model calculated in the microprocessor in the loop probe is the preset signal parameter y m (k), and the disturbance parameter d(k) = y m (k) is calculated.

[0139] In step S930, a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensor signal is sent to the controller, so that the controller calculates the residual error parameter based on the preset signal parameter and the real-time sensor signal, and judges whether the data packet is attacked and tampered based on the residual error parameter and the disturbance parameter.

[0140] Specifically, the detection loop probe sends the data packet containing the real-time sensing signal, the preset signal parameter and the disturbance parameter stored in the storage module to the controller through the communication module for the controller to perform operation and verification. The controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and determines whether the difference between the real-time sensing signal and the preset signal parameter is caused by interference due to working condition change or caused by attack on the industrial process control loop, while considering that the disturbance parameter is also subject to attack tampering, to avoid attack false alarm.

[0141] In step S940, if the similar verification instruction sent by the controller is received, attack detection is performed on the real-time control signal based on the real-time sensing signal.

[0142] Specifically, if the similar verification instruction sent by the controller is received by the loop probe, attack detection is performed on the real-time control signal u(k) based on the real-time sensing signal y(k). The specific steps of attack detection can include:

[0143] First, the loop probe calculates an error value ek based on the real-time sensing signal y(k) and the preset reference value rk, calculates an estimated control output based on the error value ek and a preset control parameter, verifies whether the real-time control signal is similar to the estimated control output, and if not, indicates that it is subject to attack tampering and triggers a second attack alarm information, and if yes, indicates that it is not subject to attack tampering and step S910 is performed.

[0144] It should be noted that in the present embodiment, the preset reference value range is a value range subjectively set by the user according to the actual situation of the industrial process control loop, wherein the preset reference value can be temperature, pressure, flow, liquid level or concentration, etc., which is not limited here.

[0145] The present embodiment, through the above scheme, specifically by obtaining the pre-processed real-time sensing signal and the corresponding real-time control signal, calculating the disturbance parameter based on the real-time sensing signal and the preset signal parameter, sending the data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and determines whether the data packet is subject to attack tampering based on the residual parameter and the disturbance parameter, and if the similar verification instruction sent by the controller is received, attack detection is performed on the real-time control signal based on the real-time sensing signal. By performing similarity verification on the real-time control signal u(k) based on the real-time sensing signal, attack false alarm caused by disturbance is effectively avoided, and the problem of attack false alarm is solved, which has important value for the security protection of the industrial process control system.

[0146] Reference Figure 10 , Figure 10 The flowchart of the signal data preprocessing of the attack detection method of the present application. Based on the above Figure 9 The step S910 of obtaining the pre-processed real-time sensing signal and the corresponding real-time control signal includes:

[0147] Step S1001, obtaining the smooth sensing signal emitted by the sensor and the smooth control signal emitted by the controller;

[0148] Specifically, under the normal operating condition of the industrial process control loop, the A / D converter installed in the detection loop probe of the industrial process control loop obtains the smooth sensing signal y(s) emitted by the sensor and the smooth control signal u(s) emitted by the controller, so as to convert the initial content of the real-time sensing signal and the real-time control signal before the sensor transmits data to the controller.

[0149] Step S1002, converting the smooth control signal and the smooth sensing signal to obtain the real-time control signal and the real-time sensing signal.

[0150] Specifically, under the normal operating condition of the industrial process control loop, the A / D converter in the detection loop probe converts the sensing signal y(s) emitted by the sensor and the smooth control signal u(s) emitted by the controller in real time, thereby obtaining the corresponding real-time sensing signal y(k) and real-time control signal u(k). Wherein, the real-time control signal corresponds to the real-time sensing signal. As an implementation manner, the real-time sensing signal y(k) and the real-time control signal u(k) are obtained by the loop probe at the same time; as another implementation manner, the real-time sensing signal y(k) and the real-time control signal u(k) are obtained by the loop probe in the order of actual situation or user setting. This embodiment takes the implementation manner of converting the real-time sensing signal y(k) and the real-time control signal u(k) by the loop probe at the same time.

[0151] Further, the step S920 of calculating the real-time sensing signal and the preset signal parameter to obtain the disturbance parameter before the step includes:

[0152] Step S1003, identifying the controlled object model based on the smooth control signal and the smooth sensing signal;

[0153] This embodiment implements the steps S1003 to S1004 between the steps S910 and S920, and in other embodiments, the steps S1003 to S1004 can also be implemented before the step S910.

[0154] Specifically, the control signal u(s) and sensor signal y(s) under normal operating conditions of the industrial process control loop are converted using an A / D converter within the loop probe. Based on the corresponding conversion results u(k) and y(k), the controlled object model is obtained offline using a classical model identification method.

[0155]

[0156] In this application, the least squares method is preferred, but other model identification methods may be used in other embodiments, and no specific limitations are made here. The Gm(s) parameters are stored in the memory of the loop probe and sent to the controller / attack detector through the communication interface;

[0157] Step S1004: Determine the preset signal parameters based on the controlled object model.

[0158] Specifically, the controlled object model G is identified offline based on u(k) and y(k). m (s), the controlled object model G m (s) parameter converted to G m (z), transforming the time series u(k) output by the controller into u(z), and then considering the time series u(z) output by the controller and the controlled object model G. m (z) Calculation model output:

[0159] y m (z)=u(z)*G m (z);

[0160] Finally, y m (z) is transformed into a time series y m (k), and the time series y m (k) serves as a preset signal parameter representing the industrial process control loop in the absence of an attack.

[0161] This embodiment, through the above-described scheme, specifically acquires the stable sensing signal emitted by the sensor and the stable control signal emitted by the controller; converts the stable control signal and the stable sensing signal to obtain the corresponding real-time control signal and the real-time sensing signal; identifies the controlled object model based on the stable control signal and the stable sensing signal; and determines the preset signal parameters based on the controlled object model. This application embodiment provides a step for generating preset signal parameters representing an industrial process control loop under unattacked conditions, which can be used as standard parameters for comparing real-time sensing signals during attack detection. The involved computational principles are simple and the computational cost is low, improving the practicality of the control system attack detection method of this invention.

[0162] refer to Figure 11 ,Figure 11 Flowchart of similarity test of attack detection method of the present application. Based on the above Figure 10 The step of attack detection on the real-time control signal based on the real-time sensing signal in the embodiment shown in step S940 comprises:

[0163] Step S1110, calculating the error value of the real-time sensing signal and the preset reference value;

[0164] Specifically, the preset reference value r(k) is a numerical range set by the user according to the actual situation of the industrial process control loop, and then the difference between r(k) and y(k) is calculated by the loop probe to obtain the error value e(k). For example, e(k) = r(k) - y(k).

[0165] Step S1120, calculating the estimated control output based on the error value and the preset control parameter;

[0166] For example, using the PID controller parameters: Kc = 2.4, Ti = 8.8, Td = 0 and the sampling time Ts = 1, the estimated control output is calculated:

[0167]

[0168] Wherein

[0169] Step S1130, checking whether the real-time control signal is similar to the estimated control output;

[0170] Specifically, similarity test is performed for the first case, at this time d(k) and y(k) are not attacked, d a (k) = d(k), y a (k) = y(k), the detector judges that the system is not attacked and tampered, then the loop probe performs secondary attack detection.

[0171] Similarity test is performed for the second case, at this time d(k) and y(k) are attacked by the same attack, d a (k) = d(k) + a(k), y a (k) = y(k) + a(k), at this time the transmission data is attacked, but the controller judges that the system is not attacked and tampered, that is, the judgment of the controller is a false positive. Then the loop probe performs secondary attack detection.

[0172] Step S1140, if not, it indicates that it is attacked and tampered, and a second attack alarm information is triggered;

[0173] Specifically, referring to Figure 12 , Figure 12The figure of similarity test result of the disturbance data of loop output and detection in the embodiment of the application subjected to the same attack. It is shown in the figure that after t = 300s, u(k) and Deviation occurs, u(k) and Cosine similarity S between the two signals:

[0174]

[0175] Wherein, k represents the current time, u(k) and Denote the time series with length k, and S changes with the signal length.

[0176] Reference Figure 13 , Figure 13 The figure of similarity calculation result of the disturbance data of loop output and detection in the embodiment of the application subjected to the same attack. It can be seen that when t = 315s, the similarity S between the two signals is lower than the threshold value Sth = 0.8, which is regarded as the system being attacked, and attack warning is performed.

[0177] If yes, it indicates that no attack tampering is suffered, and the step of converting the stationary control signal and the stationary sensing signal is performed to correspondingly obtain the real-time control signal and the real-time sensing signal.

[0178] Specifically, reference Figure 14 , Figure 14 The figure of similarity test result of the loop in the embodiment of the application under the attack-free state. It is shown in the figure that u(k) and are basically consistent, and the system is regarded as normal operation, and the step S1001 is performed.

[0179] In the embodiment, the error value is obtained by calculating the real-time sensing signal and the preset reference value; the estimated control output is obtained by calculating based on the error value and the preset control parameter; whether the real-time control signal is similar to the estimated control output is tested; if not, it indicates that attack tampering is suffered, and the second attack warning information is triggered; if yes, it indicates that no attack tampering is suffered, and the step of converting the stationary control signal and the stationary sensing signal is performed to correspondingly obtain the real-time control signal and the real-time sensing signal. By testing the similarity of the real-time control signal based on the real-time sensing signal, the attack false alarm caused by disturbance is effectively avoided, the attack missing report problem is solved, and the safety protection of the industrial process control system has important value.

[0180] In addition, the embodiment of the application also proposes a detection system, and the detection system of the application comprises:

[0181] a controller configured to receive a data packet containing a disturbance parameter, a preset signal parameter and a real-time sensing signal sent by the loop probe, and calculate a residual parameter based on the preset signal parameter and the real-time sensing signal; determine whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if not attacked and tampered, send a similarity verification instruction to the loop probe for the loop probe to perform attack detection on a real-time control signal based on the real-time sensing signal, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe;

[0182] a loop probe configured to obtain a pre-processed real-time sensing signal and a corresponding real-time control signal; calculate a disturbance parameter by comparing the real-time sensing signal with a preset signal parameter; and send a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and determines whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if receiving the similarity verification instruction sent by the controller, perform attack detection on the real-time control signal based on the real-time sensing signal.

[0183] Preferably, the controller comprises:

[0184] a receiving module configured to receive a data packet containing a disturbance parameter, a preset signal parameter and a real-time sensing signal sent by the loop probe, and calculate a residual parameter based on the preset signal parameter and the real-time sensing signal;

[0185] an attack detection module configured to determine whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter;

[0186] an instruction sending module configured to send a similarity verification instruction to the loop probe for the loop probe to perform attack detection on a real-time control signal based on the real-time sensing signal if the data packet is not attacked and tampered, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe.

[0187] Preferably, the loop probe comprises:

[0188] an obtaining module configured to obtain a pre-processed real-time sensing signal and a corresponding real-time control signal;

[0189] a calculating module configured to calculate a disturbance parameter by comparing the real-time sensing signal with a preset signal parameter;

[0190] The parameter sending module is configured to send a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and determines whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter.

[0191] The similarity checking module is configured to perform attack detection on the real-time control signal based on the real-time sensing signal if a similarity checking instruction sent by the controller is received.

[0192] In addition, the application further provides a terminal device, which comprises a memory, a processor and an attack detection program stored in the memory and executable on the processor. When the attack detection program is executed by the processor, the steps of the attack detection method are implemented.

[0193] Since the attack detection program is executed by the processor, all the technical solutions of the foregoing embodiments are adopted, and all the beneficial effects brought by all the technical solutions of the foregoing embodiments are at least achieved, which will not be repeated here.

[0194] In addition, the application further provides a computer readable storage medium, which stores an attack detection program. When the attack detection program is executed by the processor, the steps of the attack detection method are implemented.

[0195] Since the attack detection program is executed by the processor, all the technical solutions of the foregoing embodiments are adopted, and all the beneficial effects brought by all the technical solutions of the foregoing embodiments are at least achieved, which will not be repeated here.

[0196] Compared with the prior art, the attack detection method, system, terminal device and storage medium provided by the embodiments of the application receive the data packet sent by the loop probe and containing the disturbance parameter, the preset signal parameter and the real-time sensing signal, and calculate a residual parameter based on the preset signal parameter and the real-time sensing signal; based on the residual parameter and the disturbance parameter, it is judged whether the data packet is attacked and tampered with; if not, a similarity verification instruction is sent to the loop probe for the loop probe to perform attack detection on the real-time control signal corresponding to the real-time sensing signal based on the real-time sensing signal, wherein the real-time sensing signal and the real-time control signal are obtained by the loop probe at the same time. By adding a loop probe in the industrial control system, considering the case that the real-time sensing signal and the real-time control signal of the transmitted data are attacked at the same time, and adding similarity verification in the loop probe, the attack detection false negative and false positive problems can be solved, and the accuracy of attack detection is improved. Based on the scheme of the application, starting from the problem of external disturbance existing in the industrial control system in the real world, a detection system based on the loop probe is constructed, and the effectiveness of the attack detection method proposed in the application is verified on the detection system. Finally, the attack false negative rate and false alarm rate detected by the method of the application are significantly reduced.

[0197] It should be noted that in this document, the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or inherent to such a process, method, article or system. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or system including the element.

[0198] The above-mentioned application embodiment serial numbers are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0199] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as above, and includes a plurality of instructions for making a terminal device (which can be a mobile phone, computer, server, controlled terminal, or network device, etc.) execute the method of each embodiment of the application.

[0200] The above merely preferred embodiments of the present application and are not intended to limit the patent scope of the present application, any equivalent structure or equivalent process transformation made by using the content of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. An attack detection method characterized by, The attack detection method is applied to a controller interacting with a loop probe, and comprises the following steps: receiving a data packet sent by the loop probe and containing a disturbance parameter, a preset signal parameter and a real-time sensing signal, and calculating a residual parameter based on the preset signal parameter and the real-time sensing signal; judging whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if not attacked and tampered, sending a similarity checking instruction to the loop probe for attack detection on a real-time control signal based on the real-time sensing signal, including: calculating an error value by comparing the real-time sensing signal with a preset reference value; calculating an estimated control output based on the error value and a preset control parameter; checking whether the real-time control signal is similar to the estimated control output; if not, indicating that the data packet is attacked and tampered, and triggering a second attack alarm information; if yes, indicating that the data packet is not attacked and tampered, and performing a step of converting a stable control signal and a stable sensing signal to obtain the real-time control signal and the real-time sensing signal corresponding to each other and obtained by the loop probe.

2. The attack detection method of claim 1, wherein, The step of judging whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter comprises: if the residual parameter is equal to the disturbance parameter, indicating that the data packet is not attacked and tampered; if a difference between the residual parameter and the disturbance parameter exceeds a preset threshold, indicating that the data packet is attacked and tampered.

3. The attack detection method of claim 1, wherein, The step after judging whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter comprises: if attacked and tampered, triggering a first attack alarm information.

4. An attack detection method characterized by, The attack detection method is applied to a loop probe interacting with a controller, and comprises the following steps: obtaining a real-time sensing signal and a corresponding real-time control signal pre-processed; calculating a disturbance parameter by comparing the real-time sensing signal with a preset signal parameter; sending a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and judges whether the data packet is attacked and tampered based on the residual parameter and the disturbance parameter; if receiving a similarity checking instruction sent by the controller, performing attack detection on the real-time control signal based on the real-time sensing signal, including: calculating an error value by comparing the real-time sensing signal with a preset reference value; calculating an estimated control output based on the error value and a preset control parameter; checking whether the real-time control signal is similar to the estimated control output; if not, indicating that the data packet is attacked and tampered, and triggering a second attack alarm information; if yes, indicating that the data packet is not attacked and tampered, and performing a step of converting a stable control signal and a stable sensing signal to obtain the real-time control signal and the real-time sensing signal corresponding to each other.

5. The attack detection method of claim 4, wherein, The loop probe also interacts with the sensor, and the step of obtaining the pre-processed real-time control signal and real-time sensing signal comprises: obtaining smooth sensing signals sent by the sensor and smooth control signals sent by the controller; converting the smooth control signals and the smooth sensing signals to obtain the real-time control signal and the real-time sensing signal.

6. The attack detection method of claim 5, wherein, The step of calculating the real-time sensing signal and the preset signal parameter to obtain the disturbance parameter comprises: identifying the controlled object model based on the smooth control signals and the smooth sensing signals; determining the preset signal parameter based on the controlled object model.

7. A detection system characterized by, The detection system comprises a controller and a loop probe. The controller is configured to receive a data packet containing a disturbance parameter, a preset signal parameter and a real-time sensing signal sent by the loop probe, and calculate a residual parameter based on the preset signal parameter and the real-time sensing signal; determine whether the data packet is attacked and tampered with based on the residual parameter and the disturbance parameter; if not, send a similarity verification instruction to the loop probe for attack detection on a real-time control signal based on the real-time sensing signal, comprising: calculating an error value by comparing the real-time sensing signal with a preset reference value; calculating an estimated control output based on the error value and a preset control parameter; verifying whether the real-time control signal is similar to the estimated control output; if not, it indicates that the data packet is attacked and tampered with, and a second attack alarm information is triggered; if yes, it indicates that the data packet is not attacked and tampered with, and the step of converting smooth control signals and smooth sensing signals to obtain the real-time control signal and the real-time sensing signal is executed, wherein the real-time control signal corresponds to the real-time sensing signal and is obtained by conversion of the loop probe; The loop probe is configured to obtain a pre-processed real-time sensing signal and a corresponding real-time control signal; calculate a disturbance parameter by comparing the real-time sensing signal with a preset signal parameter; send a data packet containing the disturbance parameter, the preset signal parameter and the real-time sensing signal to the controller, so that the controller calculates a residual parameter based on the preset signal parameter and the real-time sensing signal, and determines whether the data packet is attacked and tampered with based on the residual parameter and the disturbance parameter; if a similarity verification instruction is received from the controller, attack detection is performed on the real-time control signal based on the real-time sensing signal, comprising: calculating an error value by comparing the real-time sensing signal with a preset reference value; calculating an estimated control output based on the error value and a preset control parameter; verifying whether the real-time control signal is similar to the estimated control output; if not, it indicates that the data packet is attacked and tampered with, and a second attack alarm information is triggered; if yes, it indicates that the data packet is not attacked and tampered with, and the step of converting smooth control signals and smooth sensing signals to obtain the real-time control signal and the real-time sensing signal is executed.

8. A terminal device, comprising: The terminal device comprises a memory, a processor, and an attack detection program stored on the memory and executable on the processor, wherein the attack detection program, when executed by the processor, implements the steps of the attack detection method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores an attack detection program, wherein the attack detection program, when executed by the processor, implements the steps of the attack detection method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Method and device for detecting false data injection attack and readable storage medium

    CN110995761A

  • Network attack detection method and device

    CN113472721A

  • Control system attack detection method, detection system, equipment and storage medium

    CN114527651A