A PLC-based industrial control network security protection method

By adopting PLC-based security protection methods in industrial control networks, determining the safety level according to the equipment type and monitoring, the problem of lack of grade protection and evaluation requirements in the prior art is solved, and efficient security protection of industrial control networks is achieved.

CN115047822BActive Publication Date: 2025-05-06BEIJING SECPOINT TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202210851268.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-20
Publication Date
2025-05-06
Estimated Expiration
2042-07-20

AI Technical Summary

Technical Problem

The existing industrial control network security protection methods lack grade protection and evaluation requirements, which leads to network equipment being susceptible to network viruses and other interferences, affecting the security of industrial control systems.

Method used

By constructing a PLC-based industrial control network security protection method, first determine its security level and evaluation requirements based on the type and function of the network equipment, and then build a network security monitoring system to detect and monitor the equipment to ensure that the equipment always runs in a preset security environment.

Benefits of technology

It effectively avoids cyber attacks and other interferences such as network viruses, ensures the security of industrial control systems and equipment, and simplifies network security management and improves protection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115047822B_ABST
    Figure CN115047822B_ABST
Patent Text Reader

Abstract

The present invention discloses a PLC-based industrial control network security protection method, which is specifically implemented as follows: Step 1, network devices are first classified according to different types and marked with serial numbers through a PLC control component; Step 2, a server system determines the corresponding security level for different network devices according to the classification information, and generates corresponding evaluation requirements at the same time; Step 3, a network security monitoring system is simultaneously constructed, and the PLC control component performs network security detection on the corresponding network devices according to the security level and evaluation requirements of different network devices and through a network security detection system, and the detected information is fed back to the PLC control component. The present invention is implemented based on level protection and evaluation requirements, firstly determining the security level of the network and system, and then performing security protection according to the basic requirements and evaluation requirements of network security. The network devices are always operated in a preset security environment, thus avoiding network attacks or other interferences such as network viruses.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial control network security protection, and specifically to a PLC-based industrial control network security protection method. Background Art

[0002] At present, with the integration of informatization and industrialization, the security issues of industrial control systems have become increasingly prominent. Once a security vulnerability appears in an industrial control system, the possibility of the industrial control system being attacked by viruses, Trojans and other threats increases, which in turn makes the industrial production control process face security threats. At present, the security protection measures taken in industrial control systems are generally to deploy firewalls between the enterprise management layer and the external network of the industrial control system network. Due to the lack of protection measures, once the firewall between the enterprise management layer and the external network is breached by the attacker, the internal network of the industrial control system can be easily controlled, so that the production data and other data in the industrial control system are stolen, or the field equipment is maliciously manipulated, affecting the normal industrial control. The PLC control system is a new generation of industrial control devices formed by introducing microelectronics technology, computer technology, automatic control technology and communication technology on the basis of the traditional sequential controller. The purpose is to replace the sequential control functions such as relays, execution logic, timing, counting, etc., and establish a flexible remote control system. It has the characteristics of strong versatility, easy use, wide adaptability, high reliability, strong anti-interference ability, and simple programming.

[0003] After searching, it was found that the patent with publication number CN102438026A discloses an industrial control network security protection method and system, which includes the following steps: in response to external network attacks, the front host performs the first layer of data filtering and access control on the external network data, the security control host caches the data through the shared storage area, performs intrusion detection on the data, promptly alarms the illegal data and notifies the hosts on both sides, the rear host performs deep filtering and access control on the data, and the legal data enters the internal network; in response to internal network attacks, the rear host performs the first layer of data filtering and access control on the internal network data, the security control host caches the data through the shared storage area, performs intrusion detection on the data, promptly alarms the illegal data and notifies the hosts on both sides, the front host performs deep filtering and access control on the data, and the legal data enters the external network.

[0004] The invention with publication number CN112839031A discloses and provides an industrial control network security protection method that can improve the security of industrial control networks, facilitate communication, prevent external attacks and intrusions, and effectively protect the safety of industrial control systems and industrial equipment. The method includes the following steps: hierarchical processing of industrial enterprise information systems, taking security protection strategy measures for data exchange in the industrial control layer; dividing the industrial control layer into multiple different automation unit areas and using firewalls for regional isolation; blocking the potential communication path of the production execution layer to the industrial control layer; and using the industrial security management platform module to establish the configuration, management, analysis, alarm and audit center of the industrial control layer network.

[0005] Currently, network security is receiving more and more attention. However, after analysis, it was found that the existing network security protection method introduces security strategies during implementation and then completes it through special network isolation areas. However, it lacks level protection and evaluation requirements, which means that the existing method involves a large number of network security products during implementation. Summary of the invention

[0006] Therefore, in order to solve the above shortcomings, the present invention provides a PLC-based industrial control network security protection method; the present invention is implemented based on the level protection and evaluation requirements, firstly the network and system are classified into security levels, and then security protection is performed according to the basic requirements and evaluation requirements of network security. The network equipment is always operated in a preset security environment, thus avoiding network attacks such as network viruses or other interference.

[0007] The present invention is implemented by constructing a PLC-based industrial control network security protection method, which is characterized by: the specific implementation is as follows;

[0008] Step 1: construct a PLC control component and a server system. The PLC control component first classifies network devices according to different types and marks serial numbers, and stores the classification information in the server system.

[0009] Step 2: The server system determines the corresponding security level for different network devices according to the obtained classification information, and generates corresponding evaluation requirements, and feeds back to the PLC control component;

[0010] Step 3, at the same time, build a network security monitoring system. The PLC control component performs network security detection on the corresponding network devices according to the security level and evaluation requirements of different network devices through the network security detection system, and feeds back the detection information to the PLC control component.

[0011] As an improvement of the above technical solution, the PLC-based industrial control network security protection method also includes the following steps: the PLC control component compares the feedback detection information with the previously obtained security level and evaluation requirements, and judges whether the detection information is within the numerical range of the security level and the evaluation requirements. If it is within the range, the network device is considered to be in a safe state; if it is not within the range, the network device is considered to be in an unsafe state; if it is considered that the network device has a network security problem, it is immediately uploaded to the server system and a warning is given.

[0012] As an improvement of the above technical solution; the described PLC-based industrial control network security protection method; in step 3, the network security monitoring system has a harmful program monitoring unit, a network attack monitoring unit, an information destruction monitoring unit, and an equipment failure monitoring unit.

[0013] As an improvement of the above technical solution; the PLC-based industrial control network security protection method; the harmful program monitoring unit is used to monitor the following events: computer virus events, worm events, Trojan horse events, zombie network events, hybrid attack program events, web page embedded malicious code events;

[0014] The network attack monitoring unit is used to monitor the following events: denial of service attack events, backdoor attack events, vulnerability attack events, network scanning and eavesdropping events, phishing events, and interference events;

[0015] The information destruction monitoring unit is used to monitor the following events: information tampering events, information counterfeiting events, information leakage events, information theft events, information loss events, and information content security events;

[0016] The equipment fault monitoring unit is used to monitor the following faults: hardware and software faults, peripheral support facility faults, and human damage events.

[0017] As an improvement of the above technical solution; the described method for protecting industrial control network security based on PLC; the server system includes a storage server, a network level protection server, and an evaluation requirement server; the storage server is used to store classified information, and the storage server communicates with the network level protection server at the same time, and the network level protection server determines the corresponding security level for different network devices; the network level protection server communicates with the evaluation requirement server, and the evaluation requirement server generates corresponding evaluation requirements.

[0018] As an improvement of the above technical solution; the described industrial control network security protection method based on PLC; the network equipment includes data storage equipment and production control system equipment; and is classified and marked with serial numbers according to data storage equipment and production control system equipment; if it is marked as a data storage device, then the harmful program monitoring unit, network attack monitoring unit, information destruction monitoring unit, and equipment failure monitoring unit in the network security monitoring system must all be cyclically monitored on it; if it is marked as a production control system device, it is only cyclically monitored by the harmful program monitoring unit, network attack monitoring unit, and equipment failure monitoring unit.

[0019] As an improvement of the above technical solution; the PLC-based industrial control network security protection method; the network security monitoring system re-detects the network equipment at regular intervals.

[0020] As an improvement of the above technical solution; the PLC-based industrial control network security protection method; the PLC control component has an identity authentication function, and when operating through the PLC control component, user authentication is required first.

[0021] As an improvement of the above technical solution; the described PLC-based industrial control network security protection method; if it is considered that the network equipment has a network security problem, it is immediately uploaded to the server system and a warning is given. At the same time, the server system sends the alarm information and the hazard source information corresponding to the alarm information to the maintenance personnel's handheld terminal device.

[0022] The present invention has the following advantages and beneficial effects: The present invention provides a PLC-based industrial control network security protection method, which is implemented based on level protection and evaluation requirements. The network and system are firstly set to a security level, and then security protection is performed according to the basic requirements and evaluation requirements of network security. The network equipment is always operated in a preset security environment, thus avoiding network attacks or other interferences such as network viruses. In addition, the industrial security management platform module of the PLC is established, which is convenient for establishment and communication, and can also prevent external attacks and intrusions, and effectively protect the safety of industrial control systems and industrial equipment. In addition, when implementing, the network equipment is classified and distinguished, which may include data storage equipment and production control system equipment; and the data storage equipment and production control system equipment are classified and marked with serial numbers; if it is marked as a data storage device, the harmful program monitoring unit, network attack monitoring unit, information destruction monitoring unit, and equipment failure monitoring unit in the network security monitoring system shall all be cyclically monitored; if it is marked as a production control system device, it shall be cyclically monitored only by the harmful program monitoring unit, network attack monitoring unit, and equipment failure monitoring unit. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 It is a schematic diagram of the implementation framework of the protection method of the present invention;

[0024] Figure 2 It is a schematic diagram of the implementation process of the protection method of the present invention.

[0025] Among them: PLC control component 100, server system 200, storage server 210, network level protection server 220, assessment requirement server 230, network security monitoring system 300, harmful program monitoring unit 310, network attack monitoring unit 320, information destruction monitoring unit 330, equipment failure monitoring unit 340. DETAILED DESCRIPTION

[0026] The following will be combined with the attached Figure 1-Figure 2 The present invention is described in detail, and the technical solutions in the embodiments of the present invention are clearly and completely described. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0027] The present invention provides a PLC-based industrial control network security protection method by improving Figure 1-Figure 2 As shown, it can be implemented in the following ways; the specific implementation is as follows;

[0028] Step 1, constructing a PLC control component 100 and a server system 200, first classifying network devices according to different types and marking serial numbers through the PLC control component, and storing the classification information in the server system 200;

[0029] Step 2, the server system 200 determines the corresponding security level for different network devices according to the obtained classification information, and generates corresponding evaluation requirements; and feeds back to the PLC control component 100;

[0030] Step 3, at the same time, a network security monitoring system 300 is constructed, and the PLC control component 100 performs network security detection on the corresponding network devices through the network security detection system according to the security level and evaluation requirements of different network devices, and feeds back the detection information to the PLC control component 100. During implementation, the network security monitoring system 300 needs to re-detect the network devices at regular intervals.

[0031] Step 4 also includes the following steps: the PLC control component 100 compares the feedback detection information with the previously obtained security level and evaluation requirements to determine whether the detection information is within the numerical range of the security level and evaluation requirements. If it is within the range, the network device is considered to be in a safe state; if it is not within the range, the network device is considered to be in an unsafe state; if it is considered that the network device has network security, it is immediately uploaded to the server system and a warning is given.

[0032] like Figure 1 As shown, the PLC-based industrial control network security protection method described in the present invention is implemented; in step 3, the network security monitoring system has a harmful program monitoring unit 310, a network attack monitoring unit 320, an information destruction monitoring unit 330, and an equipment failure monitoring unit 340.

[0033] The harmful program monitoring unit 310 is used to monitor the following events: computer virus events, worm events, Trojan horse events, botnet events, hybrid attack program events, and web page embedded malicious code events;

[0034] The network attack monitoring unit 320 is used to monitor the following events: denial of service attack events, backdoor attack events, vulnerability attack events, network scanning and eavesdropping events, phishing events, and interference events;

[0035] The information destruction monitoring unit 330 is used to monitor the following events: information tampering events, information counterfeiting events, information leakage events, information theft events, information loss events, and information content security events;

[0036] The equipment fault monitoring unit 340 is used to monitor the following faults: hardware and software faults, peripheral support facility faults, and human damage events.

[0037] When the present invention is implemented, the network equipment includes data storage equipment and production control system equipment, and is classified and marked with serial numbers according to the data storage equipment and the production control system equipment. If it is marked as a data storage device, the harmful program monitoring unit, network attack monitoring unit, information destruction monitoring unit, and equipment failure monitoring unit in the network security monitoring system must all perform cyclic monitoring on it; if it is marked as a production control system device, it is only cyclically monitored by the harmful program monitoring unit, network attack monitoring unit, and equipment failure monitoring unit.

[0038] like Figure 1As shown, the PLC-based industrial control network security protection method described in the present invention is implemented; the server system 200 includes a storage server 210, a network level protection server 220, and an evaluation requirement server 230; the storage server 210 is used to store classified information, and the storage server 210 communicates with the network level protection server 220 at the same time, and the network level protection server 220 determines the corresponding security level for different network devices; the network level protection server communicates with the evaluation requirement server 230, and the evaluation requirement server 230 generates corresponding evaluation requirements.

[0039] When the present invention is implemented, the PLC control component has an identity authentication function, and when an operation is performed through the PLC control component, user authentication is first required.

[0040] When the present invention is implemented, if it is considered that the network equipment has network security, it will be immediately uploaded to the server system and warned. At the same time, the server system will send the alarm information and the hazard source information corresponding to the alarm information to the handheld terminal device of the maintenance personnel.

[0041] The present invention has the following advantages and beneficial effects: The present invention provides a PLC-based industrial control network security protection method, which is implemented based on level protection and evaluation requirements. The network and system are firstly set to a security level, and then security protection is performed according to the basic requirements and evaluation requirements of network security. The network equipment is always operated in a preset security environment, thus avoiding network attacks or other interferences such as network viruses. In addition, the industrial security management platform module of the PLC is established, which is convenient for establishment and communication, and can also prevent external attacks and intrusions, and effectively protect the safety of industrial control systems and industrial equipment. In addition, when implementing, the network equipment is classified and distinguished, which may include data storage equipment and production control system equipment; and the data storage equipment and production control system equipment are classified and marked with serial numbers; if it is marked as a data storage device, the harmful program monitoring unit, network attack monitoring unit, information destruction monitoring unit, and equipment failure monitoring unit in the network security monitoring system shall all be cyclically monitored; if it is marked as a production control system device, it shall be cyclically monitored only by the harmful program monitoring unit, network attack monitoring unit, and equipment failure monitoring unit.

[0042] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A PLC-based industrial control network security protection method, characterized in that ; The specific implementation is as follows; Step 1, constructing a PLC control component (100) and a server system (200), first classifying network devices according to different types and marking serial numbers through the PLC control component, and storing the classification information in the server system (200); Step 2, the server system (200) determines the corresponding security level for different network devices according to the obtained classification information, and generates corresponding evaluation requirements; and feeds back to the PLC control component (100); Step 3, simultaneously constructing a network security monitoring system (300), the PLC control component (100) performs network security detection on corresponding network devices according to the security level and evaluation requirements of different network devices through the network security detection system, and feeds back the detection information to the PLC control component (100); The network security monitoring system comprises a harmful program monitoring unit (310), a network attack monitoring unit (320), an information destruction monitoring unit (330), and an equipment failure monitoring unit (340); The harmful program monitoring unit (310) is used to monitor the following events: computer virus events, worm events, Trojan horse events, zombie network events, hybrid attack program events, and web page embedded malicious code events; The network attack monitoring unit (320) is used to monitor the following events: denial of service attack events, backdoor attack events, vulnerability attack events, network scanning and eavesdropping events, phishing events, and interference events; The information destruction monitoring unit (330) is used to monitor the following events: information tampering events, information counterfeiting events, information leakage events, information theft events, information loss events, and information content security events; The equipment fault monitoring unit (340) is used to monitor the following faults: hardware and software faults, peripheral support facility faults, and human damage events; Network equipment includes data storage equipment and production control system equipment; And they are classified and marked with serial numbers according to data storage devices and production control system equipment; if they are marked as data storage devices, they shall be cyclically monitored by the harmful program monitoring unit, network attack monitoring unit, information destruction monitoring unit and equipment failure monitoring unit in the network security monitoring system; if they are marked as production control system equipment, they shall be cyclically monitored only by the harmful program monitoring unit, network attack monitoring unit and equipment failure monitoring unit.

2. According to claim 1, a PLC-based industrial control network security protection method is characterized by: The method further comprises the following steps: the PLC control component (100) compares the fed-back detection information with the previously obtained security level and evaluation requirements, and judges whether the detection information is within the numerical range of the security level and the evaluation requirements; if it is within the range, the network device is considered to be in a safe state; if it is not within the range, the network device is considered to be in an unsafe state; If the network device is considered to have network security problems, it will be immediately uploaded to the server system and a warning will be issued.

3. According to the PLC-based industrial control network security protection method of claim 1, it is characterized by: The server system (200) includes a storage server (210), a network level protection server (220), and an evaluation requirement server (230); the storage server (210) is used to store classified information, and the storage server (210) communicates with the network level protection server (220) at the same time, and the network level protection server (220) determines the corresponding security level for different network equipment; the network level protection server communicates with the evaluation requirement server (230), and the evaluation requirement server (230) generates corresponding evaluation requirements.

4. According to the PLC-based industrial control network security protection method of claim 1, it is characterized by: The network security monitoring system (300) is required to re-detect the network equipment at regular intervals.

5. According to the PLC-based industrial control network security protection method of claim 1, it is characterized by: The PLC control component has an identity authentication function, and user authentication is required first when operating through the PLC control component.

6. According to claim 2, a PLC-based industrial control network security protection method is characterized by: If the network equipment is considered to have network security problems, it will be immediately uploaded to the server system and a warning will be given. At the same time, the server system will send the alarm information and the hazard source information corresponding to the alarm information to the maintenance personnel's handheld terminal device.

Citation Information

Patent Citations

  • Industrial control network security protection method and system

    CN102438026A

  • Industrial control network security protection system and method

    CN112839031A

  • Industrial information security authentication system

    CN105471901A

  • Computer network security control system and control method thereof

    CN112087429A

  • Protection monitoring method and equipment

    CN113761502A