Time synchronization attack detection method for industrial wireless networks
By proposing three hidden time-synchronous attack models and detection methods based on improved Bayesian models, the problem of industrial wireless networks being vulnerable to delayed attacks is solved, effective detection and classification of full life cycle delayed attacks is achieved, and detection accuracy is improved.
Patent Information
- Application Number
- CN202211109362.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-13
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2042-09-13
AI Technical Summary
Industrial wireless networks are vulnerable to delay attacks. The existing detection methods cannot effectively detect full-life cycle delay attacks without significant changes in time characteristics, and do not consider the impact of interference and noise in wireless environments.
Three more hidden time synchronization attack models are proposed, including one-way full-life cycle delay attack, two-way full-life cycle delay attack and one-way non-full-life cycle delay attack. An attack detection method based on an improved Bayesian model is adopted, and characteristic information such as transmission rate, transmission delay, transmission success rate and time synchronization time interval are used to reduce the impact of wireless signal noise interference.
实现了对三种攻击模式的有效检测和分类,提高了检测准确率,降低了无线信号噪声干扰的影响。
Smart Images

Figure CN115499841B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and specifically relates to a method for detecting time synchronization attacks for industrial wireless networks. Background Art
[0002] In recent years, with the increasing urgency of demands such as customized production and energy conservation and emission reduction in industrial production, intelligent manufacturing has become the focus of attention in the industrial and academic circles. In the era of intelligent manufacturing, factories need more flexible and intelligent production lines to meet the diverse customized needs of users and the rapidly changing market demands. Industrial wireless technology, with its advantages of mobility, flexibility, low cost, etc., has become the core enabling technology for intelligent manufacturing and is widely used in process industries such as petroleum, chemical, and metallurgy, as well as discrete manufacturing industries such as automotive, electronics, and robotics. Currently, for process industries, there are three major industrial wireless standards in the world: WirelessHART (IEC62591), ISA100.11a (IEC 62734), and WIA-PA (IEC 62601). For discrete industries, the WIA-FA (IEC 62948) standard led by China is the only industrial wireless technology in the world for high-speed control applications in discrete manufacturing. In order to ensure high real-time and high reliability of transmission, the data link layer of industrial wireless networks uses time division multiple access (TDMA) to avoid transmission conflicts and ensure the reception and transmission of data at specified times. Thus, ensuring the unity of the whole network clock is the primary condition for ensuring the normal operation of industrial wireless networks, and high-precision time synchronization is the key. Time synchronization attack (TSA) is an attack against the network time synchronization mechanism, which can cause time deviation between network nodes, reduce the performance of systems, services, or devices, and even cause catastrophic consequences. Due to the openness of the wireless medium, wireless networks are more vulnerable to attacks such as interference, spoofing, and tampering during the time synchronization stage. Once industrial wireless networks are subjected to malicious attacks such as data tampering, replay attacks, and delay attacks during the time synchronization stage, it will cause the clocks of nodes and gateways to be inconsistent, resulting in a decline in network communication performance and even network collapse.
[0003] Most time synchronization attacks can be resolved by using appropriate cryptographic techniques. For example, providing authentication for each exchanged message to prevent attackers from masquerading as other nodes and tampering with the content of the exchanged messages, and adding sequence numbers to beacon messages or other messages to prevent replay attacks. However, the delay attack is a time synchronization attack that cannot be resolved by cryptographic techniques. The delay attack interferes with synchronization by delaying and changing the transmission time to amplify the deviation between the node and the actual time. All current time synchronization mechanisms are vulnerable to delay attacks. Most methods for detecting delay attacks select time-related features as the basis for judgment, such as clock offset, end-to-end delay, etc. However, for full-life cycle delay attacks with no obvious changes in time features, these methods are obviously not suitable. Secondly, most detection methods do not consider the impact of interference and noise in the wireless environment on the detection model, and the model generalization is poor. Thirdly, most of the proposed delay attack models assume that the node has been captured, which is difficult for attackers to launch attacks and has strong assumptions. Summary of the Invention
[0004] The main objective of the present invention is to overcome the shortcomings and deficiencies of the prior art, and provide a time synchronization attack detection method for industrial wireless networks, including proposing three relatively concealed time synchronization attack models, and an attack detection method based on an improved Bayesian model, and finally realizing the detection of three attacks.
[0005] The technical solution adopted by the present invention to achieve the above objective is: a time synchronization attack detection method for industrial wireless networks, including the following steps:
[0006] Construct different types of time synchronization attack patterns;
[0007] Perform time synchronization attack detection on the wireless network to obtain the type of time synchronization attack.
[0008] The time synchronization attack model includes a one-way full-life cycle delay attack, which is used for non-time source nodes to perform one-way time synchronization with time source nodes through beacon frames or time synchronization frames.
[0009] The specific process of the one-way full-life cycle delay attack is as follows:
[0010] 3-1) When the non-time source node is turned on, the attacker performs directional interference on it, so that the non-time source node cannot receive the beacon frame / time synchronization frame;
[0011] 3-2) At a certain moment, the attacker obtains a beacon frame or time synchronization frame of one time source node, then stops the interference, and replays the beacon frame / time synchronization frame after a delay of e time;
[0012] 3-3) When the time synchronization period arrives, return to step 3-1), which causes the non-time source node to be always e time slower than the time source node.
[0013] The time synchronization attack mode includes a two-way full life cycle delay attack, where the non-time source node performs one-way time synchronization with the time source node through beacon frames / time synchronization frames before joining the network, and performs two-way time synchronization with the time source node in the first superframe after joining the network, and then performs one-way time synchronization again.
[0014] The specific process of the two-way full life cycle delay attack is as follows:
[0015] 5-1) When the non-time source node is turned on, the attacker performs directional interference on it, so that the non-time source node cannot receive beacon frames or time synchronization frames;
[0016] 5-2) At a certain moment, the attacker obtains a beacon frame / time synchronization frame of one time source node, then stops the interference, and replays the beacon frame / time synchronization frame after a delay of e time;
[0017] 5-3) When the non-time source node joins the network, it performs two-way time synchronization with the time source node in the first superframe and obtains the frame transmission time TxDelay. At this time, the non-time source node will be f time faster than the time source node;
[0018] 5-4) When the next time synchronization period arrives, the attacker performs directional interference and replays the beacon frame / time synchronization frame after a delay of f time;
[0019] 5-5) When the time synchronization period arrives each time, return to step 5-4), which causes the non-time source node to be always f time faster than the time source node.
[0020] The time synchronization attack model includes a one-way non-full life cycle delay attack, where the non-time source node only performs one-way time synchronization with the time source node after joining the network.
[0021] The specific process of the one-way non-full life cycle delay attack is as follows:
[0022] 7-1) When a time synchronization period arrives, the attacker performs directional interference on the non-time source node and obtains the beacon frame or time synchronization frame of the time source node;
[0023] 7-2) The attacker replays the beacon frame or time synchronization frame after a delay time g, where g is less than the time synchronization accuracy;
[0024] 7-3) Whenever the time synchronization period arrives, the attacker replays the beacon frame or time synchronization frame after adding a delay time Δg to the previous attack, where Δg is less than the time synchronization accuracy. The cumulative delay stops increasing after reaching e, resulting in the non-time source nodes always being e time slower than the time source nodes.
[0025] Performing time synchronization attack detection on the wireless network to obtain the type of time synchronization attack, specifically by obtaining network observation information and performing attack detection through a Bayesian model, including the following steps:
[0026] a) Calculate the prior probability:
[0027]
[0028] where I represents the indicator function, y i represents the classification information corresponding to c k Y represents the classification information, and c k represents the classification content, including one-way full life cycle delay attack, two-way full life cycle delay attack, one-way non-full life cycle delay attack, and no attack; k represents the number of classifications, and N represents the number of samples containing observation information and corresponding classifications;
[0029] b) Calculate the conditional probability:
[0030] The set of possible values of the j-th feature x (j) is The maximum likelihood estimate of the conditional probability P(X (j) = a jl |Y = c k ) is
[0031]
[0032] where X (j) represents the j-th feature information, x (j) represents the j-th feature of the i-th sample; a jl represents the l-th value that the j-th feature may take; the feature is one of the observation information, and the observation information includes transmission rate, transmission delay, transmission success rate, and time synchronization time interval;
[0033] c) Introduce the noise covariance matrix and convert the conditional probability P(X (j) = a jl |Y = c k ) into a j×j matrix
[0034]
[0035] is the noise covariance matrix of the observation information under the k-th classification, For the corresponding information matrix; introducing the information matrix into to obtain
[0036]
[0037]
[0038] σ j represents the j-th variance;
[0039] 3.4) Attack detection is classified as
[0040]
[0041] y represents one of the classifications of one-way full life cycle delay attack, two-way full life cycle delay attack, one-way non-full life cycle delay attack, and no attack.
[0042] A time synchronization attack detection system for industrial wireless networks includes a memory and a processor; the memory is used to store a computer program; the processor is used to implement the time synchronization attack detection method for industrial wireless networks when executing the computer program.
[0043] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the time synchronization attack detection method for industrial wireless networks.
[0044] The present invention has the following beneficial effects and advantages:
[0045] Based on in-depth analysis of the time synchronization mechanism of industrial wireless networks, the present invention proposes three time synchronization attack models, which achieve relatively concealed delay attacks on the premise that nodes are not captured; for the above attack models, an attack detection method based on an improved Bayesian model is proposed. The model includes four types of characteristic information: transmission rate, transmission delay, transmission success rate, and time synchronization time interval, and can effectively detect and classify attacks; characterizing the wireless channel noise as a characteristic information matrix and introducing it into the Bayesian model reduces the influence of wireless signal noise interference on attack detection and improves the detection accuracy. Description of the Drawings
[0046] Figure 1 is a schematic diagram of the one-way time synchronization delay attack model of the present invention;
[0047] Figure 2 is a schematic diagram of the two-way time synchronization delay attack model of the present invention;
[0048] Figure 3 It is the attack flow chart of the unidirectional full life cycle delay attack of the present invention;
[0049] Figure 4 It is the attack flow chart of the bidirectional full life cycle delay attack of the present invention;
[0050] Figure 5 It is the attack flow chart of the unidirectional non-full life cycle delay attack of the present invention;
[0051] Figure 6 It is the attack detection flow chart of the present invention based on the improved Bayesian model. Detailed implementation manners
[0052] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0053] In order to enable those skilled in the art of this technology to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of this application.
[0054] Industrial wireless networks mostly adopt a time synchronization mechanism based on the sender-receiver model. Non-time source nodes calibrate their local clocks by receiving beacon frames / time synchronization frames from time source nodes to achieve the purpose of time synchronization. For the time synchronization based on the sender-receiver model, launching a delay attack usually requires first capturing the sender, that is, the time source node; then controlling the time source node to delay the beacon frame / time synchronization frame for a period of time and send it to the receiver, that is, the non-time source node; the non-time source node receives the delayed beacon frame / time synchronization frame and calibrates its local clock, thereby generating a time deviation. However, most of the main application scenarios of industrial wireless networks are in indoor enclosed spaces such as factories and workshops. Time source nodes such as gateway devices, routing devices, and access devices are usually deployed in specific spaces in factories or workshops and are maintained by special personnel, and it is difficult to capture them.
[0055] Figure 1 and Figure 2 show an attack model that can launch a delay attack without capturing the time source node. Figure 1The figure shows a unidirectional time synchronization delay attack model. When the time source node sends a beacon frame / time synchronization frame, the attacker uses a directional antenna to interfere with the non-time source node, so that the non-time source node cannot receive the beacon frame / time synchronization frame. After a period of delay, the attacker sends the beacon frame / time synchronization frame of the time source node, that is, launches a replay attack. At this time, the non-time source node synchronizes its time according to the received beacon frame / time synchronization frame, resulting in a time deviation.
[0056] Figure 2 For the bidirectional time synchronization delay attack model, when the time source node sends a beacon frame / time synchronization frame, the attacker uses a directional antenna to interfere with the non-time source node, so that the non-time source node cannot receive the beacon frame / time synchronization frame. After a period of delay, the attacker sends the beacon frame / time synchronization frame of the time source node. After receiving the beacon frame / time synchronization frame, the non-time source node sends a request frame to the time source node. After receiving the request frame, the time source node sends a response frame containing TxDelay to the non-time source node. The non-time source node synchronizes its time according to the received T asn and TxDelay. The above attack can increase TxDelay, resulting in a time deviation in subsequent unidirectional time synchronization. The specific attack processes of the three time synchronization attacks are as follows:
[0057] (1) Unidirectional full-life cycle delay attack: The non-time source node performs unidirectional time synchronization with the time source node through beacon frames / time synchronization frames. When the non-time source node is turned on, the attacker performs directional interference on it, so that the non-time source node cannot receive the beacon frame / time synchronization frame; at a certain moment, the attacker obtains a beacon frame / time synchronization frame of one time source node, then stops the interference, and replays the beacon frame / time synchronization frame after a delay of e time; subsequently, repeat the above operations whenever the time synchronization period arrives, resulting in the non-time source node always being e time slower than the time source node. The attack process is as Figure 3 shown.
[0058] (2) Bidirectional full - life - cycle delay attack: Before joining the network, the non - time - source node performs one - way time synchronization with the time - source node through beacon frames / time synchronization frames. In the first super - frame after joining the network, it performs two - way time synchronization with the time - source node, and then performs one - way time synchronization again. The attacker conducts directional interference on the non - time - source node when it is turned on, so that the non - time - source node cannot receive beacon frames / time synchronization frames. At a certain moment, the attacker obtains a beacon frame / time synchronization frame of one time - source node, then stops the interference, and replays the beacon frame / time synchronization frame after a delay of e time. When the non - time - source node joins the network, in the first super - frame, it performs two - way time synchronization with the time - source node and obtains the frame transmission time TxDelay. At this time, the non - time - source node will be f time faster than the time - source node. When the next time - synchronization period arrives, the attacker conducts directional interference and replays the beacon frame / time synchronization frame after a delay of f time. Subsequently, whenever the time - synchronization period arrives, the above operation is repeated, resulting in the non - time - source node always being f time faster than the time - source node. The attack process is as Figure 4 shown.
[0059] (3) Unidirectional non - full - life - cycle delay attack: After the non - time - source node joins the network, it only performs one - way time synchronization with the time - source node. When a certain time - synchronization period arrives, the attacker conducts directional interference on the non - time - source node and obtains the beacon frame / time synchronization frame of the time - source node. To make the attack more concealed, the attacker replays the beacon frame / time synchronization frame after a very short delay of g time (g is generally less than the time - synchronization accuracy). Subsequently, whenever the time - synchronization period arrives, the attacker replays the beacon frame / time synchronization frame after increasing a delay time of Δg (Δg is generally less than the time - synchronization accuracy) compared with the previous time, until the cumulative time delay reaches e and then stops increasing, resulting in the non - time - source node always being e time slower than the time - source node. The attack process is as Figure 5 shown.
[0060] As Figure 6 shown, for the above three time - synchronization attacks, this embodiment proposes an attack detection method based on an improved Bayesian model, including the following steps:
[0061] S1. Calculate the prior probability. Make a conditional independence assumption for the conditional probability distribution, that is
[0062]
[0063] where X represents the observed information, x represents the observed value, X (n) represents the nth feature of the observed information, Y represents the classification information, c represents the specific classification content, and k represents the number of classifications.
[0064] Calculate the posterior probability distribution according to Bayes' theorem
[0065]
[0066] That is
[0067]
[0068] Therefore, the attack detection and classification can be expressed as
[0069]
[0070] In the above formula, the denominator is the same for all c k So
[0071]
[0072] Among them, the prior probability and conditional probability in the above formula can be estimated by the maximum likelihood estimation method. The maximum likelihood estimation of the prior probability P(Y = c k ) is
[0073]
[0074] N represents the number of samples, and K represents the number of classifications; among them, the sample is the data set used when training the detection model, specifically referring to a data pair containing 4 types of feature data sets x (j) (transmission rate, transmission delay, transmission success rate, and time synchronization time interval) and the corresponding 1 classification y i (unidirectional full life cycle delay attack, bidirectional full life cycle delay attack, unidirectional non-full life cycle delay attack, or no attack), and there are a total of N such data pairs.
[0075] Since the results of attack detection are divided into 4 cases: unidirectional full life cycle delay attack, bidirectional full life cycle delay attack, unidirectional non-full life cycle delay attack, and no attack, the prior probability can be expressed as
[0076]
[0077] S2. Calculate the conditional probability. Let the set of possible values of the j-th feature x (j) be Since the model extracts 4 types of feature information: transmission rate, transmission delay, transmission success rate, and time synchronization time interval, the value of j is 1-4. The maximum likelihood estimation of the conditional probability P(X (j) = a jl |Y = c k ) is
[0078]
[0079] Among them, x (j) represents the j-th feature of the i-th sample; a jlDenote the l-th value that the j-th feature may take, s j Denote the value sequence number; I denotes the indicator function.
[0080] S3. Introduce the noise covariance matrix. Convert the conditional probability P(X (j) = a jl |Y = c k ) into a j×j matrix
[0081]
[0082] Let be the noise covariance matrix of the observation information under the k-th classification, be the corresponding information matrix. To fully consider the influence of the noise covariance on the conditional probability, this paper introduces the information matrix into to obtain as shown in the formula
[0083]
[0084]
[0085] σ j denote the j-th variance.
[0086] S4. Calculate the detection result. Finally, the attack detection classification can be expressed as
[0087]
[0088] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0089] The present application is described with reference to the flowchart of the method according to the embodiments of the present application. It should be understood that each process in the flowchart can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes.
[0090] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the function specified in one process Figure 1 or functions specified in multiple processes.
[0091] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the function specified in one process Figure 1 or functions specified in multiple processes.
[0092] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific embodiments of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A time synchronization attack detection method for industrial wireless networks, characterized in that: The following steps are involved: Construct different types of time synchronization attack models; Perform time synchronization attack detection on the wireless network to obtain the type of time synchronization attack; The time synchronization attack model includes a one-way full lifecycle delay attack, which is used for non-time source nodes to perform one-way time synchronization with time source nodes through beacon frames or time synchronization frames; The time synchronization attack model includes a two-way full life cycle delay attack, which is used for non-time source nodes to perform one-way time synchronization with the time source node through beacon frames / time synchronization frames before joining the network, and perform two-way time synchronization with the time source node in the first superframe after joining the network, and then perform one-way time synchronization; The time synchronization attack model includes a one-way non-full life cycle delay attack, which is used for non-time source nodes to perform only one-way time synchronization with the time source node after joining the network; The method of performing time synchronization attack detection on the wireless network to obtain the type of time synchronization attack is specifically to obtain network observation information and perform attack detection through a Bayesian model, including the following steps: a) Calculate the prior probability: Where I represents the indicator function, y i Indicates c k The corresponding classification information, Y represents the classification information, c k Indicates the classification content, including one-way full life cycle delay attack, two-way full life cycle delay attack, one-way non-full life cycle delay attack, and no attack; k represents the number of categories, and N represents the number of samples containing observation information and corresponding categories; b) Calculate the conditional probability: The jth feature x (j) The set of possible values is Conditional probability P(X (j) =a jl |Y=c k The maximum likelihood estimate of ) is Among them, X (j) represents the jth feature information, x (j) represents the jth feature of the i-th sample; a jl Indicates the lth value that the jth feature may take; the feature is one of the observation information, and the observation information includes transmission rate, transmission delay, transmission success rate, and time synchronization time interval; c) Introduce the noise covariance matrix and transform the conditional probability P(X (j) =a jl |Y=c k ) is converted into a j×j matrix is the noise covariance matrix of the observation information under the kth category, for The corresponding information matrix; the information matrix Introduced get σ j represents the jth variance; 3.4) Attack detection is classified into y represents a category among one-way full life cycle delay attack, two-way full life cycle delay attack, one-way non-full life cycle delay attack, and no attack.
2. The time synchronization attack detection method for industrial wireless networks according to claim 1 is characterized in that: The one-way full life cycle delay attack is as follows: 3-1) The attacker performs directional interference on the non-time source node while it is turned on, so that the non-time source node cannot receive the beacon frame / time synchronization frame; 3-2) At a certain moment, the attacker obtains a beacon frame or time synchronization frame from a time source node, then stops interfering and replays the beacon frame / time synchronization frame after a delay of e time; 3-3) Whenever the time synchronization period arrives, return to step 3-1), so that the non-time source node is always slower than the time source node.
3. The time synchronization attack detection method for industrial wireless networks according to claim 1 is characterized in that: The bidirectional full life cycle delay attack is as follows: 5-1) The attacker performs directional interference on the non-time source node while it is turned on, so that the non-time source node cannot receive the beacon frame or time synchronization frame; 5-2) At a certain moment, the attacker obtains the beacon frame / time synchronization frame of a time source node, then stops interfering and replays the beacon frame / time synchronization frame after a delay of e time; 5-3) When a non-time source node joins the network, it performs bidirectional time synchronization with the time source node in the first superframe and obtains the frame transmission time TxDelay. At this time, the non-time source node will be faster than the time source node by time f; 5-4) When the next time synchronization cycle arrives, the attacker conducts directional interference and delays the replay of the beacon frame / time synchronization frame for a time period of f; 5-5) Whenever the time synchronization period arrives, return to step 5-4), so that the non-time source node is always faster than the time source node by time.
4. The time synchronization attack detection method for industrial wireless networks according to claim 1 is characterized in that: The one-way non-full life cycle delay attack is as follows: 7-1) When a certain time synchronization period arrives, the attacker conducts directional interference on the non-time source node and obtains the beacon frame or time synchronization frame of the time source node; 7-2) The attacker replays the beacon frame or time synchronization frame after a delay of time g, where g is less than the time synchronization accuracy; 7-3) Whenever the time synchronization cycle arrives, the attacker replays the beacon frame or time synchronization frame after adding a delay of Δg compared to the previous attack. Δg is less than the time synchronization accuracy. The cumulative delay will not increase until it reaches e, resulting in the non-time source node always being e time slower than the time source node.
5. A time synchronization attack detection system for industrial wireless networks, characterized in that: It comprises a memory and a processor; the memory is used to store a computer program; the processor is used to implement the time synchronization attack detection method for industrial wireless networks as described in any one of claims 1 to 4 when executing the computer program.
6. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by the processor, the time synchronization attack detection method for industrial wireless networks as described in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Relay attack defense method and system based on pulse flight time ranging
CN109655817A
Complex network synchronization control method under aperiodic DoS attack
CN112995154A