A method, device and equipment for detecting industrial control flow
By analyzing the response behavior in industrial control flow, combining the target equipment and relevant parameters of the request, the problem of complex and inefficient industrial control flow detection in the prior art is solved, and a simple and efficient detection effect is achieved.
Patent Information
- Application Number
- CN202210846677.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-05
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-07-05
AI Technical Summary
The existing industrial control traffic detection method is based on request messages, resulting in complex detection and low efficiency.
By analyzing the response behavior in industrial control traffic, combining the target device and the relevant parameters of the request, the legality or abnormality of the request is determined.
It realizes simple and efficient detection of industrial control traffic, which is more universal and efficient than the method of directly analyzing request messages.
Smart Images

Figure CN115225375B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial control technology, and in particular, to a method, device, and equipment for detecting industrial control traffic. Background Art
[0002] Detecting abnormal traffic in industrial control traffic is one of the important means to protect industrial control systems.
[0003] Currently, various request messages in industrial control traffic are usually identified and detected through technologies such as black and white list matching mechanisms, security threat modeling, or machine learning, that is, the request messages are detected to determine whether the industrial control traffic is abnormal.
[0004] However, the detection method of industrial control traffic based on request messages as the basis for detecting industrial control traffic is very complex and has low efficiency. Summary of the Invention
[0005] This application provides a method, device, and equipment for detecting industrial control traffic. Combining the principle that different devices respond differently to different input request messages, simple and efficient detection of industrial control traffic is achieved by analyzing the response behavior in industrial control traffic.
[0006] In a first aspect, this application provides a method for detecting industrial control traffic, including:
[0007] Receiving industrial control traffic, where the industrial control traffic includes a first request and a second request;
[0008] Determining that there is a first response to the first request in the industrial control traffic, then determining a first detection result of the first request based on the first response;
[0009] Determining that there is no response to the second request in the industrial control traffic, then determining a second detection result of the second request based on a first policy, where the first policy defines the legitimacy of the second request based on the target device and relevant parameters of the second request, and the second request is generated by the target device.
[0010] Optionally, determining the first detection result of the first request based on the first response includes:
[0011] If the first response matches a preset abnormal response type, then determining that the first request is an abnormal access of the first type;
[0012] If the first response does not match any of the preset abnormal response types, determining that the first request is legal.
[0013] Optionally, determining the second detection result of the second request based on the first policy includes:
[0014] If the target device actively disconnects the session, then determine that the second request is an abnormal access of the second type;
[0015] If the target device does not actively disconnect the session, then determine the second detection result based on the communication mode of the target device and the second request.
[0016] Optionally, the determining the second detection result based on the communication mode of the target device and the second request includes:
[0017] If the communication mode of the target device is not a one-way communication mode, then determine that the second request is an abnormal access of the third type;
[0018] If the communication mode of the target device is a one-way communication mode, then determine that the second request is legal or the second request is an abnormal access of the fourth type based on the relevant parameters of the second request.
[0019] Optionally, the method further includes:
[0020] Record the number of times of abnormal access of each type;
[0021] For each type of abnormal access, when the number of times of abnormal access of this type reaches the alarm times threshold of this type of abnormal access, an alarm is made.
[0022] Optionally, the target device is an industrial control embedded device.
[0023] In a second aspect, the present application further provides a detection device for industrial control traffic, including:
[0024] A receiving unit, configured to receive industrial control traffic, where the industrial control traffic includes a first request and a second request;
[0025] A first detection unit, configured to determine that there is a first response to the first request in the industrial control traffic, then determine the first detection result of the first request based on the first response;
[0026] A second detection unit, configured to determine that there is no response to the second request in the industrial control traffic, then determine the second detection result of the second request based on a first policy, where the first policy defines the legality of the second request based on the target device and the relevant parameters of the second request, and the second request is generated by the target device.
[0027] Optionally, the first detection unit is specifically configured to:
[0028] If the first response matches a preset abnormal response type, then determine that the first request is an abnormal access of the first type;
[0029] If the first response does not match any of the preset abnormal response types, determine that the first request is legal.
[0030] Optionally, the second detection unit includes:
[0031] A first determination subunit, configured to determine that the second request is an abnormal access of a second type if the target device actively disconnects the session;
[0032] A second determination subunit, configured to determine the second detection result based on the communication mode of the target device and the second request if the target device does not actively disconnect the session.
[0033] Optionally, the second determination subunit is specifically configured to:
[0034] If the communication mode of the target device is not a one-way communication mode, determine that the second request is an abnormal access of a third type;
[0035] If the communication mode of the target device is a one-way communication mode, determine that the second request is legal or the second request is an abnormal access of a fourth type based on the relevant parameters of the second request.
[0036] Optionally, the device further includes:
[0037] A recording unit, configured to record the number of times of abnormal access of each type;
[0038] An alarm unit, configured to perform an alarm when the number of times of abnormal access of each type reaches the alarm times threshold of the abnormal access of that type.
[0039] Optionally, the target device is an industrial control embedded device.
[0040] It should be noted that for the specific implementation manner and achieved effects of the device provided in the second aspect, reference may be made to the description of the relevant embodiments of the method shown in the first aspect.
[0041] In a third aspect, the present application further provides an electronic device, which includes a processor and a memory:
[0042] The memory is used to store a computer program;
[0043] The processor is configured to execute the method provided in the first aspect according to the computer program.
[0044] In a fourth aspect, the present application further provides a computer-readable storage medium, which is used to store a computer program, and the computer program is used to execute the method provided in the first aspect.
[0045] As can be seen, the present application has the following beneficial effects:
[0046] The present application provides a method for detecting industrial control traffic. This method may include, for example: an industrial control traffic detection device determines whether a request is abnormal based on the response situation of requests in the industrial control traffic. For example, if the industrial control traffic detection device determines that there is a first response to a first request in the industrial control traffic, then it determines a first detection result of the first request based on the first response; if the industrial control traffic detection device determines that there is no response to a second request in the industrial control traffic, then it determines a second detection result of the second request based on a first policy. The first policy defines the legitimacy of the second request (such as whether the second request is legal or abnormal, and if abnormal, what specific type of abnormality it is) based on the target device and relevant parameters of the second request. The second request is generated by the target device. It can be seen that this method makes full use of the principle that the target device has different responses to different requests. The industrial control traffic detection device analyzes the response behavior of the target device to infer whether the request of the target device is a malicious attack message. Compared with the method of directly analyzing the complex features of requests to detect requests, it is simpler, more efficient, and has stronger universality. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.
[0048] Figure 1 It is a schematic diagram of an industrial control system applicable to the embodiments of the present application;
[0049] Figure 2 For Figure 1 it is a schematic structural diagram of the anomaly detection and protection device 10 shown;
[0050] Figure 3 It is a schematic flow diagram of a method for detecting industrial control traffic provided by the embodiments of the present application;
[0051] Figure 4 It is a schematic flow diagram of an example of the method for detecting industrial control traffic provided by the embodiments of the present application;
[0052] Figure 5 It is a schematic diagram of a scenario provided by the embodiments of the present application;
[0053] Figure 6 It is a schematic diagram of another scenario provided by the embodiments of the present application;
[0054] Figure 7 A schematic diagram of another scenario provided by an embodiment of the present application;
[0055] Figure 8 A schematic diagram of yet another scenario provided by an embodiment of the present application;
[0056] Figure 9 A schematic diagram of another scenario provided by an embodiment of the present application;
[0057] Figure 10 A schematic diagram of another scenario provided by an embodiment of the present application;
[0058] Figure 11 A schematic diagram of the structure of a detection device for industrial control traffic provided by an embodiment of the present application;
[0059] Figure 12 A schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0060] To make the above objects, features, and advantages of the present application more obvious and understandable, the following further describes the embodiments of the present application in detail with reference to the accompanying drawings and specific implementation manners. It can be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. In addition, it should be noted that for the sake of description, only the parts related to the present application are shown in the drawings, not all the structures.
[0061] With the development of Internet technology, network security has become the focus of people's attention. Detecting abnormal traffic is one of the important means to protect network security. For industrial control systems that communicate based on the Transmission Control Protocol / Internet Protocol (TCP / IP) network between industrial hosts (such as operator stations, engineer stations, etc.) and industrial control embedded devices (such as Remote Terminal Unit (RTU), Programmable Logic Controller (PLC), Distributed Control System (DCS), etc.), it is also necessary to ensure network security through anomaly detection.
[0062] It can be understood that there are many examples of abnormal industrial control systems caused by single or limited malformed data packets, but the resulting industrial enterprise security incidents are relatively few; however, after the industrial control system is invaded, there are relatively many cases where the industrial control embedded device runs in an unexpected state for a long time and causes losses.
[0063] At present, the abnormal detection of industrial control traffic in industrial control systems usually adopts blacklist and whitelist matching mechanism, security threat modeling or machine learning and other technologies to identify and detect various request messages (or input messages) of industrial control traffic, that is, to determine whether the industrial control traffic is abnormal based on the detection and analysis of the request messages. However, the detection method of industrial control traffic based on request messages has problems such as low efficiency and low detection accuracy due to the various and complex characteristics of industrial control traffic request messages under different abnormalities.
[0064] Based on this, the industrial control traffic detection method proposed in the embodiment of the present application mainly provides a complete, reasonable and efficient anomaly detection mechanism based on the analysis of the response (also called output) of the industrial control traffic. Specifically, the method may include, for example: the industrial control traffic detection device determines whether the request is abnormal based on the response of the request in the industrial control traffic. For example, the industrial control traffic detection device determines that there is a first response to the first request in the industrial control traffic, then, based on the first response, a first detection result of the first request is determined; the industrial control traffic detection device determines that there is no response to the second request in the industrial control traffic, then, based on the first strategy, a second detection result of the second request is determined, the first strategy defines the legitimacy of the second request based on the target device and the relevant parameters of the second request, and the second request is generated by the target device.
[0065] It can be seen that the method provided in the embodiment of the present application makes full use of the principle that the target device responds differently to different requests. The industrial control traffic detection device analyzes the response behavior of the target device and infers whether the request of the target device is a malicious attack message. Compared with the method of detecting requests by directly analyzing the complex characteristics of the requests, it is simpler and more efficient, and has stronger universality.
[0066] It is understandable that the method provided in the embodiment of the present application can be run on Figure 1 The abnormality detection protection device 10 shown. Figure 1As shown in the figure, this is the scenario applicable to the embodiments of the present application. This scenario not only includes the anomaly detection and protection device 10, but may also include: industrial control embedded devices, a host computer 20, and a switch 30. Optionally, in a scenario with an anomaly attack, an attacker device 40 may also be included. Among them, the industrial control embedded devices, the host computer 20, and the attacker device 40 can all be connected to the anomaly detection and protection device 10 through the switch 30. Among them, the industrial control embedded devices and the host computer 20 output normal traffic, and the attacker device 40 outputs attack traffic. Whether it is normal traffic or attack traffic, the mirrored traffic after being processed by the switch 30 is input into the anomaly detection and protection device 10. The anomaly detection and protection device 10 executes the method provided by the embodiments of the present application, and realizes anomaly detection of industrial control traffic based on the response situation in the mirrored traffic output by the switch 10. If the anomaly detection and protection device 10 determines that there is an anomaly, it can block the attack by sending blocking traffic to the switch 30, etc., to ensure the security of the industrial control embedded devices and the host computer 20 as much as possible. Among them, the industrial control embedded devices and the host computer 20 may include at least one industrial control embedded device and one host computer (which may also be referred to as an industrial host).
[0067] Among them, the anomaly detection and protection device 10, as an independently operable device, may also be integrated in other devices (such as the switch 30 or the industrial control embedded devices and the host computer 20) in the form of a functional module. As Figure 2 shown, the anomaly detection and protection device 10 may include, for example: a control interface unit 11, a mirrored port network traffic capture unit 12, an industrial control protocol identification unit 13, an industrial protocol analysis unit 14, an industrial control embedded device response analysis unit 15, and a blocking traffic generation and sending unit 16. Among them, the control interface unit 11 can be understood as a human-machine interaction interface for device configuration and information management; the mirrored port network traffic capture unit 12 is used to obtain network interface traffic. For example, in the Figure 1 scenario shown in the figure, it obtains the network interface traffic of the switch 30. This traffic may include the mirrored traffic corresponding to the normal traffic output by the industrial control embedded devices and the host computer 20, or may also include the mirrored traffic corresponding to the attack traffic output by the attacker device 40; the industrial control protocol identification unit 13 is not only used to distinguish industrial control traffic and traditional Internet Technology (IT) traffic, but can also further identify the industrial control protocol and forward the corresponding traffic to the corresponding industrial protocol analysis unit 14; the industrial protocol analysis unit 14 is used to analyze the industrial protocol, especially for analyzing the response messages output by the industrial control embedded devices and the host computer 20 (such as industrial control embedded devices); the industrial control embedded device response analysis unit 15 is used to implement the detection of industrial control traffic based on the method provided by the embodiments of the present application. Specifically, reference can be made to the following Figure 3Detailed description of the illustrated embodiment; the traffic blocking and generation and sending unit 16, when detecting malicious malformed attack packets, not only gives an alarm in time, but also sends packets to block the traffic as much as possible to further protect the industrial control system.
[0068] In specific implementation, the industrial control embedded device response analysis unit 15 can configure parameters such as the statistical threshold for various abnormal accesses and the setting of the time window when executing the embodiments of the present application in the control interface unit 11. First, according to the industrial control protocol recognition unit 13, the traffic of the mirror port is split, and the industrial control traffic within the time window is batch-processed in units of the time window. The determination logic is shown in Figure 4 as shown.
[0069] It should be noted that Figure 2 in the illustrated abnormal detection and protection device 10, the industrial control embedded device response analysis unit 15 is the core unit for the embodiments of the present application to be implemented; the remaining units are all for assisting the industrial control embedded device response analysis unit 15 to implement the method provided by the embodiments of the present application, and will not be introduced in detail in the embodiments of the present application.
[0070] In the embodiments of the present application, a reverse analysis idea for detecting malicious malformed attack packets in the industrial control network is proposed, that is, according to the correlation between the request message input by the industrial control embedded device and the output response, instead of directly performing malformed detection and analysis on the input message, the output response behavior and message are studied reversely. According to the analysis results of the response behavior of the industrial control embedded device and the output response message, it is inferred whether there is a security threat in the industrial control system.
[0071] It should be noted that the main body for implementing the industrial control traffic detection method can be the industrial control traffic detection device provided by the embodiments of the present application, and this device can be carried on an electronic device or a functional module of an electronic device. The electronic device in the embodiments of the present application can be any device capable of implementing the industrial control traffic detection method in the embodiments of the present application. Corresponding to the above Figure 1 and Figure 2 illustrated examples, the industrial control traffic detection device can also be understood as the aforementioned industrial control embedded device response analysis unit 15, and the electronic device carrying the industrial control traffic detection device can be understood as the abnormal detection and protection device 10 including the industrial control embedded device response analysis unit 15.
[0072] To facilitate understanding of the specific implementation of the industrial control traffic detection method provided by the embodiments of the present application, the following will be described with reference to the drawings.
[0073] Figure 3Schematic flowchart of a method for detecting industrial control traffic provided by an embodiment of the present application. This method is applied to a device for detecting industrial control traffic, which can detect the industrial control traffic generated by a target device. The target device can be a terminal device such as an industrial control embedded device or a personal computer (PC). As Figure 3 shown, the method may include the following S101 to S102:
[0074] S101. If it is determined that there is a first response to a first request in the industrial control traffic, then based on the first response, determine a first detection result of the first request;
[0075] S102. If it is determined that there is no response to a second request in the industrial control traffic, then based on a first policy, determine a second detection result of the second request. The first policy defines the legitimacy of the second request based on relevant parameters of the target device and the second request, and the second request is generated by the target device.
[0076] It can be understood that the object processed in this method is the received industrial control traffic, which includes a first request and a second request. Among them, the request with a response in the industrial control traffic can be recorded as the first request in S101, and the response corresponding to the first request is recorded as the first response in S101; similarly, the request without a response in the industrial control traffic can be recorded as the second request in S102.
[0077] It should be noted that the execution of S101 and S102 has no order limit. S101 can be executed first and then S102, or S102 can be executed first and then S101, or S101 and S102 can be executed simultaneously.
[0078] It should be noted that before S101 and S102, the method may further include: S100. Determine whether there is a response to the request in the industrial control traffic. If there is, record the request as the first request and execute S101; otherwise, record the request as the second request and execute S102. Specifically, when implemented, the basis for judgment in S100 can be the characteristics of the industrial control traffic, such as the Internet Protocol (IP) address, port number, etc. of the industrial control traffic.
[0079] For S101, if it is determined that there is a first response to the first request in the industrial control traffic, then the first detection result of the first request can be determined based on the first response. As an example, S101 may include, for example: If the first response matches a preset abnormal response type, then it is determined that the first request is an abnormal access of the first type; if the first response does not match any of the preset abnormal response types, it is determined that the first request is legal. That is, the first detection result can be that the first request is legal or the first request is abnormal. Among them, the preset abnormal response types may include, but are not limited to: the response with an incorrect engineering password input in the S7COMM protocol, the abnormal response obtained by writing data to an incorrect coil in Modbus TCP, and the abnormal response obtained by requesting an error service in the Common Industrial Protocol (CIP). The preset abnormal response types are usually clearly defined in the protocol specifications and only need to be set in advance without the need for learning and adaptation similar to the whitelist mechanism according to the customer's on-site environment.
[0080] If the first request is abnormal, as an example, all the abnormalities determined based on S101 can be recorded as an abnormal type, and the type of this abnormality can be recorded as the first type, for example. As another example, if the first request is abnormal, the abnormal type of the first request can also be determined based on the abnormal response type in the preset abnormal response types that matches the first response, and the first detection result includes the specific abnormal type of this first request.
[0081] For S102, if it is determined that there is no response to the second request in the industrial control traffic, then the second detection result of the second request can be determined based on the first policy. As an example, S102 may include, for example: If the target device actively disconnects the session, then it is determined that the second request is an abnormal access of the second type; if the target device does not actively disconnect the session, then the second detection result is determined based on the communication mode of the target device and the second request.
[0082] Among them, when it is determined that the target device does not actively disconnect the session, the determining the second detection result based on the communication mode of the target device and the second request may include: If the communication mode of the target device is not a one-way communication mode, then it is determined that the second request is an abnormal access of the third type; if the communication mode of the target device is a one-way communication mode, then it is determined that the second request is legal or the second request is an abnormal access of the fourth type based on the relevant parameters of the second request. Among them, the specific implementation manner of determining that the second request is legal or the second request is an abnormal access of the fourth type based on the relevant parameters of the second request can be implemented in any manner in the prior art, and the embodiments of the present application do not make specific limitations.
[0083] It should be noted that after the industrial control traffic obtains the detection result through the method provided in the embodiment of the present application, the number of abnormal accesses of each type can also be recorded based on the detection result; thus, for each type of abnormal access, when the number of abnormal accesses of this type reaches the warning number threshold of this type of abnormal access, a warning is issued. In this way, through reasonable warnings, the security of the industrial control system can be effectively improved, and to a certain extent, the work efficiency of the security protection staff can be improved. Moreover, this warning can be designed as a trigger condition for automatically implementing security protection operations such as sending blocked traffic, improving the intelligent level of the industrial control system, especially the detection part of the industrial control traffic in the industrial control system.
[0084] To more clearly illustrate the method provided in the embodiment of the present application, the following will Figure 4 give an exemplary description of the embodiment of the present application. Refer to Figure 4 , the embodiment of the present application may include, for example:
[0085] S41, parameter configuration.
[0086] For example, S41 may include setting the warning number thresholds of various types.
[0087] S42, obtain the mirror port network data traffic in the traffic.
[0088] It should be noted that S42 is a step executed when the target device is an industrial control embedded device, and when the target device is a terminal device such as a PC, S42 may not be executed.
[0089] S43, determine whether the mirror port network data traffic is industrial control traffic. If so, execute S44; otherwise, ignore the mirror port network data traffic.
[0090] It should be noted that S43 is a step that may not be executed when the target device is an industrial control embedded device. When the target device is a terminal device such as a PC, the execution of S43 can filter non-industrial control traffic (such as control plane traffic).
[0091] It should be noted that S41 to S43 can be understood as the preparation steps for implementing the embodiment of the present application.
[0092] S44, obtain the industrial control traffic under the time window.
[0093] It can be understood that periodic industrial control traffic detection can be achieved by setting a time window. For example, the time window can be 30 minutes. Then, the detection process provided in the embodiment of the present application can be performed on the industrial control traffic obtained within every 30 seconds every 30 seconds.
[0094] S45. Determine whether there is an application layer response to the request in the industrial control traffic. If there is, execute S46; otherwise, execute S49.
[0095] S46. Determine whether the response to the request matches a preset abnormal response type. If it does, execute S48; otherwise, execute S47.
[0096] S47. Determine that the request is legal.
[0097] Among them, the request being legal can mean that the request message is legal and the corresponding communication mode is legal.
[0098] S48. Determine that the request is an abnormal access.
[0099] S49. Determine whether the target device actively disconnects the session. If it does, execute S48; otherwise, execute S50.
[0100] S50. Determine whether the communication mode of the target device is a one-way communication mode. If it is, execute S51; otherwise, execute S48.
[0101] S51. Based on the relevant parameters of the second request, determine whether the request is abnormal. If it is, execute S48; otherwise, execute S47.
[0102] It should be noted that after S48, S52 and S53 may also be included:
[0103] S52. According to S46, S49, S50 and S51, record the types and corresponding frequencies of the abnormal accesses detected in each step.
[0104] For example, when S46 triggers S48, record 1 abnormal access of the first type; when S49 triggers S48, record 1 abnormal access of the second type; when S50 triggers S48, record 1 abnormal access of the third type; when S51 triggers S48, record 1 abnormal access of the fourth type.
[0105] S53. Perform an alarm according to the frequency corresponding to the abnormal access type and the alarm frequency threshold corresponding to this abnormal access type.
[0106] It should be noted that the alarm frequency thresholds corresponding to different abnormal access types can be the same or different. The frequencies of the recorded abnormal access types can be valid only in the current time window, or can be valid in a preset number of time windows. For different abnormal access types, the valid times of the recorded occurrence frequencies can be the same or different. The frequency recorded for an abnormal access type during its validity period accumulates continuously as it is detected.
[0107] It should be noted that according to actual needs, the abnormal access types, the alarm count thresholds for various abnormal access types, and the number of valid time windows for various types of abnormal access types can be flexibly configured.
[0108] It can be seen that through the method provided by the embodiments of the present application, the abnormal detection of industrial control traffic can be simply and effectively achieved by analyzing and judging the response situation of requests in industrial control traffic.
[0109] In the method provided by the embodiments of the present application, the logical process of detecting industrial control traffic can be summarized as follows: First, according to the application layer response behavior of the industrial control embedded device to its requests, it is divided into two situations: having a response and having no response; Second, for the situation where the industrial control embedded device has an application layer response, it can be further analyzed whether it is a response to a normal request or an abnormal request. If it is a response to a normal request, it can be determined that the current request message is a legal message and the communication method is also legal, that is, a normal industrial control embedded device request and response communication; If it is a predefined abnormal response message, such as Figure 5 the response with an incorrect engineering password input in the S7COMM protocol shown, such as Figure 6 the abnormal response obtained by writing data to an incorrect coil in the Modbus TCP protocol shown, and such as Figure 7The abnormal responses obtained from the CIP protocol request error service shown, etc. These types of abnormal response messages are usually clearly defined in the protocol specification and only need to be preset in the industrial control traffic detection device provided in the embodiments of the present application, without the need to perform learning and adaptation of a whitelist mechanism similar to that based on the customer's on-site environment. Such abnormal access is defined as the first type (also referred to as type D) of abnormal access in the embodiments of the present application. Thirdly, for the situation where the industrial control embedded device has no application layer response, it is possible to infer the legitimacy of the request message it received based on whether the embedded device actively disconnects the session. If the industrial control embedded device actively disconnects the request, it is considered that a malformed abnormal data packet with a malicious attack nature that does not meet expectations has been received. To avoid further impact, the industrial control embedded device actively disconnects the current communication. Such abnormal access is defined as the second type (also referred to as type C) of abnormal access in the embodiments of the present application; if the industrial control embedded device does not actively disconnect the request, it is necessary to further consider whether it is caused by a specific communication mode, such as multicast communication or one-way communication, etc.; if it is not a specific one-way communication that causes the industrial control embedded device not to respond, it may be that the session communication is actively disconnected by the request initiator (not necessarily TCP, it may also be UDP or a layer 2 protocol). Such abnormal access is defined as the third type (also referred to as type B) of abnormal access in the embodiments of the present application. If it is a specific communication mode that causes the situation of no response and the industrial control embedded device does not actively disconnect the session, then it is possible to further determine whether the request is abnormal based on the prior art. For example, integrate the protocol specification (or convention) into the detection engine, and determine whether the request is an industrial control malformed packet based on the on-site specification constraints and historical traffic. If it is determined to be a malformed message, it is recorded as the fourth type (also referred to as type A) of abnormal access; otherwise, it is determined to be a legitimate request message and communication mode. It should be noted that although the embodiments of the present application analyze the response output behavior of the industrial control embedded device to reverse-infer whether the request message is abnormal, it is not mutually exclusive with the detection method of directly analyzing whether the request message is malformed and abnormal.
[0110] Optionally, after analyzing the industrial control traffic in the current time window according to the above process, an alarm is issued for abnormal access that exceeds the alarm count threshold, which can be flexibly adapted to a variety of application scenarios.
[0111] It can be seen that the embodiments of the present application reverse-infer different response situations of the response data packet based on the correlation between the requests and responses of the industrial control embedded device, achieving the effect of detecting whether there are malicious attack malformed data packets in the industrial control system.
[0112] The following describes the situations that may be involved in the embodiments of the present application in combination with specific scenario embodiments.
[0113] Scenario Embodiment 1: The industrial control embedded device does not respond to continuous malicious malformed input data packets.
[0114] The scenario of malformed data packets in this embodiment is as follows Figure 8 shown. A malicious attacker, as a Modbus TCP client, continuously sends malicious Modbus TCP malformed data packets to an industrial control embedded device. After the attacker actively disconnects the current TCP connection, a new TCP connection is established to send the next Modbus TCP malformed attack packet. Although the industrial control embedded device used in this embodiment normally receives requests for each TCP connection establishment, it never responds to malformed and abnormal input request messages.
[0115] In the method provided by the embodiment of the present application, it is possible to first determine whether the scenario to which the current embodiment belongs is a situation where the industrial control embedded device has no application layer response. The determination result is yes. Therefore, after obtaining the industrial control traffic in the time window, the first conditional judgment enters the branch where the result is no. Thereafter, since the industrial control embedded device does not actively disconnect the current connection, the second conditional judgment enters the branch where the result is no. Since the Modbus TCP request in the current embodiment belongs to the typical "request - response" interaction mode and does not belong to the situation of one - way communication, the third conditional judgment enters the branch where the result is no. In summary, it is finally determined that the Modbus TCP malformed data packet in each TCP connection is an abnormal access of the third type (or type B).
[0116] Scenario Embodiment Two: The industrial control embedded device actively disconnects the connection for malformed data packets.
[0117] Two typical scenarios related to this embodiment include Figure 9 the scenario where a certain model of Rockwell PLC shown actively sends a TCP.RST message to disconnect the current TCP connection after receiving an incorrect CIP request; the scenario where a certain model of Siemens PLC shown actively sends a TCP.RST message to disconnect the current TCP connection after receiving a malformed S7COMM protocol request. Both of these scenarios belong to the situation where the industrial control embedded device actively disconnects the connection.
[0118] In the method provided by the embodiment of the present application, it is possible to first determine whether the scenario to which the current embodiment belongs is a situation where the industrial control embedded device has no application layer response (i.e., does not output any application layer response messages). The determination result is yes. Therefore, in the first conditional judgment of obtaining the industrial control traffic in the time window, it enters the branch where the result is no. Since the scenarios to which this embodiment belongs are all self - protection behaviors of the industrial control embedded device that actively sends a TCP.RST rejection packet to disconnect the current connection after receiving malicious malformed request messages to avoid deeper attacks. Therefore, it is finally determined that each TCP connection contains CIP malformed data packets as shown in Figure 9 or as shown in Figure 10The shown S7COMM deformed data packet is an abnormal access of the second type (or C type) once.
[0119] Scenario Embodiment 3: The industrial control embedded device returns a predefined abnormal response packet (i.e., matching the preset abnormal response type).
[0120] Three typical scenarios related to this embodiment are described herein: Figure 5 The shown Siemens PLC of a certain model returns a password verification error response packet during the password brute - force attack (the value of the password field is deformed) due to continuously receiving incorrect passwords; Figure 6 When continuously writing data to an incorrect coil based on the Modbus TCP protocol, the Modbus TCP server returns a response message indicating a request exception; Figure 7 The shown Rockwell PLC of a certain model returns a service request exception response after receiving an incorrect service request. These three scenarios all belong to the situation where the industrial control embedded device returns a predefined abnormal response to a deformed input data packet.
[0121] In the method provided by the embodiment of the present application, it can first be determined whether the scenario to which the current embodiment belongs is a situation where the industrial control embedded device has an application layer response. If the determination result is yes, and since the types of abnormal response packets stipulated by different protocol specifications are finitely countable, when it is found that the return information of the industrial control embedded device is a response to an abnormal request, it can be inferred that there is a deformed data packet of the first type (or D type) in the current industrial control system.
[0122] It should be noted that the method provided by the embodiment of the present application can further infer more detailed types of network exceptions in the current industrial control system according to the specific content of the abnormal response message: for example Figure 5 The described scenario can be further inferred as a password brute - force attack on the S7COMM protocol, Figure 6 The described scenario can be further inferred as continuous writing to an incorrect coil of the Modbus TCP protocol, Figure 7 The described scenario can be further inferred as a service with an abnormal CIP protocol request.
[0123] It should be noted that for the abnormal access of the fourth type, there are already relatively sufficient embodiments in the prior art, so the embodiments corresponding to the abnormal access of the fourth type will not be elaborated herein. The abnormal access of the fourth type and the detection process of the abnormal access of the fourth type are only proposed for the complete description of the embodiment of the present application. The malicious deformed input packet detection technology is not mutually exclusive with the request - based detection method provided by the embodiment of the present application.
[0124] Scenario Embodiment 4: Distinguish occasional misoperations of staff from continuous malicious deformed message attacks based on an alarm count threshold (which can also be called a statistical threshold).
[0125] During the operation process, there may occasionally be input errors. That is to say, some industrial control traffic is generated by the operation of staff. For example, during the process of inputting the engineering password of a certain model of Siemens PLC, it is possible to input the wrong password several times. In response to this situation, although several abnormal accesses of the first type are recorded within the time window, as long as the threshold of this type of abnormal access is not reached, no warning will be issued for the malicious deformed data attack on the industrial control system, which can effectively reduce the false alarm rate and improve the usability and flexibility of the method provided by the embodiments of the present application.
[0126] In summary, the embodiments of the present application focus on the analysis and research of the output response information of industrial control embedded devices. By analyzing various conditions of different types of output response messages, it is inferred which type of malicious deformed attack packets exist in the industrial control system. At the same time, the method provided by the embodiments of the present application is not mutually exclusive with the mainstream detection technology based on the input deformed messages of industrial control embedded devices, and can effectively supplement and improve the abnormal detection ability of the existing industrial control system.
[0127] In the embodiments of the present application, not only a reverse analysis idea for detecting malicious deformed attack packets in the industrial control system is proposed: according to the correlation between the request message of the industrial control embedded device and the output response, instead of directly performing deformed detection and analysis on the request message, the response behavior and message in the industrial control traffic are studied reversely. According to the analysis results of the response behavior and message of the industrial control embedded device, it is inferred whether there is a security threat in the industrial control system. Moreover, the embodiments of the present application classify various abnormal accesses in various response behavior and output message scenarios of the industrial control embedded device: classify various abnormal behaviors and response messages of the industrial control embedded device from the completeness of classification, and infer the category of the abnormal deformed input message by analyzing the characteristics of each type of response message. In addition, although the embodiments of the present application start from the analysis of the response message of the industrial control embedded device to detect the abnormal type of the request message, it is not mutually exclusive with the research method of directly analyzing whether the request message in the industrial control traffic is deformed. Therefore, the embodiments of the present application can analyze whether there is a security threat of malicious deformed input packets in the industrial control system from both the input and output directions at the same time, and give full play to the advantages of the two types of abnormal detection technologies for deformed packets. Moreover, the determination mechanism of the one-way communication mode in the embodiments of the present application can avoid misjudging the legal communication mode of one-way communication in the industrial control system as abnormal access, enhance the application scope of the method provided by the embodiments of the present application, and effectively reduce the false alarm rate. Moreover, different alarm count thresholds are set for different types of abnormal response behaviors of the industrial control embedded device in the embodiments of the present application, which can not only achieve refined management of the alarm, but also effectively distinguish the occasional misoperation of the staff from the attack threat of continuous malicious deformed data packets in the industrial control system.
[0128] Correspondingly, the embodiment of the present application further provides an industrial control traffic detection device 1100, as Figure 11 shown. The device 1100 may include:
[0129] A first detection unit 1101, configured to determine that there is a first response to a first request in the industrial control traffic, and then determine a first detection result of the first request based on the first response;
[0130] A second detection unit 1102, configured to determine that there is no response to a second request in the industrial control traffic, and then determine a second detection result of the second request based on a first policy, where the first policy defines the legality of the second request based on the target device and relevant parameters of the second request, and the second request is generated by the target device.
[0131] The device 1100 may further include a receiving unit, configured to receive industrial control traffic, where the industrial control traffic includes a first request and a second request.
[0132] Optionally, the first detection unit 1101 is specifically configured to:
[0133] If the first response matches a preset abnormal response type, determine that the first request is an abnormal access of the first type;
[0134] If the first response does not match any of the preset abnormal response types, determine that the first request is legal.
[0135] Optionally, the second detection unit 1102 includes:
[0136] A first determination subunit, configured to determine that the second request is an abnormal access of the second type if the target device actively disconnects the session;
[0137] A second determination subunit, configured to determine the second detection result based on the communication mode of the target device and the second request if the target device does not actively disconnect the session.
[0138] Optionally, the second determination subunit is specifically configured to:
[0139] If the communication mode of the target device is not a one-way communication mode, determine that the second request is an abnormal access of the third type;
[0140] If the communication mode of the target device is a one-way communication mode, determine that the second request is legal or the second request is an abnormal access of the fourth type based on the relevant parameters of the second request.
[0141] Optionally, the device 1100 further includes:
[0142] A recording unit for recording the number of abnormal accesses of each type;
[0143] An alarm unit for performing an alarm for each type of abnormal access when the number of abnormal accesses of this type reaches the alarm count threshold of this type of abnormal access.
[0144] Optionally, the target device is an industrial control embedded device.
[0145] It should be noted that for the specific implementation manner and achieved effects of the industrial control traffic detection device 1100 provided in the embodiments of the present application, reference can be made to Figure 3 or Figure 4 the description of the related embodiments of the industrial control traffic detection method shown.
[0146] In addition, the embodiments of the present application further provide an electronic device 1200, as Figure 12 shown, the electronic device 1200 includes a processor 1201 and a memory 1202:
[0147] The memory 1202 is used to store a computer program;
[0148] The processor 1201 is used to execute the method provided in the embodiments of the present application according to the computer program.
[0149] In addition, the embodiments of the present application further provide a computer-readable storage medium, and the computer-readable storage medium is used to store a computer program, and the computer program is used to execute the method provided in the embodiments of the present application.
[0150] From the description of the above embodiments, those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, and this computer software product can be stored in a storage medium, such as read-only memory (English: read-only memory, ROM) / RAM, magnetic disk, optical disc, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or some parts of the embodiments of the present application.
[0151] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments and device embodiments, since they are basically similar to method embodiments, they are described relatively simply. For the relevant parts, reference can be made to the descriptions in the method embodiments. The device and system embodiments described above are only illustrative. The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative efforts.
[0152] The above are only the preferred embodiments of the present application and are not intended to limit the protection scope of the present application. It should be noted that for those of ordinary skill in the art in the technical field of the present application, without departing from the premise of the present application, several improvements and refinements can also be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for detecting industrial control flow, characterized in that, Including: Receiving industrial control traffic, where the industrial control traffic includes a first request and a second request; Determining that there is a first response to the first request in the industrial control traffic, and then determining a first detection result of the first request based on the first response; Determining that there is no response to the second request in the industrial control traffic, and then determining a second detection result of the second request based on a first policy, where the first policy defines the legality of the second request based on the target device and relevant parameters of the second request, and the second request is generated by the target device; where, determining the second detection result of the second request based on the first policy includes: if the target device actively disconnects the session, then determining that the second request is an abnormal access of the second type; if the target device does not actively disconnect the session, then determining the second detection result based on the communication mode of the target device and the second request.
2. The method according to claim 1, characterized in that, The determining the first detection result of the first request based on the first response includes: If the first response matches a preset abnormal response type, then determining that the first request is an abnormal access of the first type; If the first response does not match any of the preset abnormal response types, determining that the first request is legal.
3. The method according to claim 1, characterized in that, The determining the second detection result based on the communication mode of the target device and the second request includes: If the communication mode of the target device is not a unidirectional communication mode, then determining that the second request is an abnormal access of the third type; If the communication mode of the target device is a unidirectional communication mode, then determining that the second request is legal or the second request is an abnormal access of the fourth type based on the relevant parameters of the second request.
4. The method according to any one of claims 1 - 3, characterized in that, The method further includes: Recording the number of times of each type of abnormal access; For each type of abnormal access, when the number of times of this type of abnormal access reaches the warning number threshold of this type of abnormal access, giving an alarm.
5. The method according to any one of claims 1 - 3, characterized in that, The target device is an industrial control embedded device.
6. An industrial control flow detection device, characterized in that, Including: A receiving unit, configured to receive industrial control traffic, where the industrial control traffic includes a first request and a second request; A first detection unit, configured to determine that there is a first response to the first request in the industrial control traffic, and then determine a first detection result of the first request based on the first response; A second detection unit, configured to determine that there is no response to the second request in the industrial control traffic, and then determine a second detection result of the second request based on a first policy, where the first policy defines the legality of the second request based on the target device and relevant parameters of the second request, and the second request is generated by the target device; where, determining the second detection result of the second request based on the first policy includes: if the target device actively disconnects the session, then determining that the second request is an abnormal access of the second type; if the target device does not actively disconnect the session, then determining the second detection result based on the communication mode of the target device and the second request.
7. The device according to claim 6, characterized in that, The first detection unit is specifically configured to: If the first response matches a preset abnormal response type, determine that the first request is an abnormal access of the first type; If the first response does not match any of the preset abnormal response types, determine that the first request is legal.
8. An electronic device, characterized in that, The electronic device includes a processor and a memory: The memory is used to store computer programs; The processor is used to execute the method according to any one of claims 1-5 based on the computer program.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and the computer program is used to execute the method according to any one of claims 1-5.
Citation Information
Patent Citations
Network attack security processing method and device and computer device
CN111698214A