A defense strategy determination method based on industrial control network flow data
By clustering and risk assessment of industrial control network traffic data, a risk defense mapping library is constructed, which solves the problem of insufficient industrial control network defense strategies in existing technologies and achieves more efficient network attack defense.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA ELECTRONICS CORP 6TH RES INST
- Filing Date
- 2022-12-26
- Publication Date
- 2026-05-19
AI Technical Summary
In existing technologies, industrial control network defense strategies based on historical experience are ineffective in dealing with malicious attacks on industrial control networks, resulting in reduced security.
By acquiring archived traffic data from industrial control network nodes, K-means clustering and hierarchical clustering algorithms are used for data clustering and risk assessment, a risk defense mapping library is constructed, and a customized network attack defense mechanism is formulated.
It improves the security of industrial control networks, enabling more accurate identification and response to network attacks, and reducing resource waste and information security issues.
Smart Images

Figure CN115859180B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial control network security, and more specifically, to a method for determining defense strategies based on industrial control network traffic data. Background Technology
[0002] With the rapid development of industrialization, industrial control networks have become the core for controlling a large number of various industrial control network nodes. However, due to the openness and sharing characteristics of industrial control networks, they are likely to be subject to malicious attacks and damage.
[0003] In existing technologies, when formulating network attack defense mechanisms based on malicious attacks and damage to industrial control networks, they are usually based on historical handling methods, i.e., experience, of past malicious attack events. However, the inventors found in their research that, due to the diverse types and increasing number of industrial control network nodes involved, if network attack defense mechanisms are designed solely based on historical handling experience, the resulting network defense strategies may fail to achieve effective network defense due to the limitations and randomness of experience, thereby reducing the security of the entire industrial control network. Summary of the Invention
[0004] In view of this, the purpose of this invention is to provide a method for determining defense strategies based on industrial control network traffic data, so as to improve the security of the entire industrial control network.
[0005] This application provides a method for determining defense strategies based on industrial control network traffic data. The method includes:
[0006] Obtain at least one archived industrial control network traffic data of the target industrial control network node;
[0007] The K-means clustering algorithm is used to perform business scenario clustering on the at least one archived industrial control traffic data to obtain a traffic business scenario vector describing the business scenario to which each archived industrial control traffic data belongs;
[0008] For each of the archived industrial control traffic data, a first risk coefficient for the archived industrial control traffic data is determined from the strategy table used to store the first risk defense strategy;
[0009] Based on the first risk coefficient of each archived industrial control traffic data, a hierarchical clustering algorithm is performed on each archived industrial control traffic data to obtain a first risk classification vector for each archived industrial control traffic data, wherein the first risk classification vector is used to describe the risk level of the archived industrial control traffic data.
[0010] Based on the first risk classification vector of each archived industrial control traffic data and the business scenario to which it belongs in the traffic business scenario vector, a risk defense mapping library for the first risk defense strategy is constructed.
[0011] A network attack defense mechanism for the target industrial control network node is constructed based on the aforementioned risk defense mapping library.
[0012] Optionally, the step of using the K-means clustering algorithm to perform business scenario clustering processing on the at least one archived industrial control traffic data to obtain a traffic business scenario vector describing the business scenario to which each archived industrial control traffic data belongs includes:
[0013] Obtain the business scenario classification label for each of the at least one archived industrial control traffic data;
[0014] After clustering each of the archived industrial control traffic data's business scenario classification labels using the K-means clustering algorithm, the business scenario classification label groups are arranged according to preset scenario weights, and the business scenario classification label groups serve as the traffic business scenario vector.
[0015] Optionally, the step of performing hierarchical clustering on each of the archived industrial control traffic data based on a first risk coefficient to obtain a first risk classification vector for each of the archived industrial control traffic data includes:
[0016] The archived industrial control traffic data whose values of the first risk coefficient belong to the same preset range are clustered into the same risk level to obtain the first risk level label of each archived industrial control traffic data;
[0017] The first risk level label of each archived industrial control traffic data is arranged according to the preset risk level weight to obtain the first risk level label group, and the first risk level label group is used as the first risk classification vector.
[0018] Optionally, after constructing a risk defense mapping library for the first risk defense strategy based on the first risk classification vector of each archived industrial control traffic data and the respective business scenario to which it belongs in the traffic business scenario vector, the method further includes:
[0019] Determine whether the success rate of the first risk defense in the risk defense mapping library of the first risk defense strategy is higher than the success rate of the second risk defense in the risk defense mapping library of the second risk defense strategy, wherein the second risk defense strategy is a historically constructed risk defense strategy;
[0020] If the success rate of the first risk defense is higher than the success rate of the second risk defense, the first risk defense strategy will be stored as the target risk defense strategy.
[0021] If the success rate of the first risk defense is not higher than the success rate of the second risk defense, the second risk defense strategy will be stored as the target risk defense strategy.
[0022] Optionally, obtaining at least one archived industrial control network traffic data of the target industrial control network node includes:
[0023] Obtain a first industrial control network traffic data acquisition instruction for a target industrial control network node, wherein the first industrial control network traffic data acquisition instruction includes a first expected acquisition content and operator identity information, and the operator identity information is used to indicate the target operator's permissions;
[0024] A set of traffic acquisition strategies is determined based on the target industrial control network node and the target operator's permissions. The set of traffic acquisition strategies corresponds to the target industrial control network node, and the set of traffic acquisition strategies includes at least one traffic acquisition strategy. Each traffic acquisition strategy includes the correspondence between the industrial control network traffic's own permissions and the traffic acquisition method permissions.
[0025] If the first expected content satisfies the industrial control network traffic permissions included in the target traffic acquisition strategy, then the second expected content is acquired based on the first expected content and the traffic acquisition method permissions included in the target traffic acquisition strategy, wherein the target traffic acquisition strategy belongs to the traffic acquisition strategies included in the traffic acquisition strategy set.
[0026] A second industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second expected acquisition content according to the second industrial control network traffic data acquisition instruction, wherein the second industrial control network traffic data acquisition instruction includes the second expected acquisition content, and the second expected acquisition content includes the at least one archived industrial control network traffic data;
[0027] The step of obtaining the second desired content based on the first desired content and the traffic acquisition method permissions included in the target traffic acquisition strategy includes:
[0028] If the first expected content to be obtained corresponds to a low-risk traffic use, then the traffic extraction instruction corresponding to the target industrial control network node is determined based on the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy.
[0029] The second expected content is generated based on the traffic extraction instruction and the first expected content.
[0030] If the first expected content to be obtained corresponds to a high-risk traffic purpose, then according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, the command code corresponding to the first expected content to be obtained is generated.
[0031] Generate the second desired content based on the command code and the first desired content; or,
[0032] If the first expected content to be obtained corresponds to a high-risk traffic purpose, then according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, the command code corresponding to the first expected content to be obtained is generated.
[0033] Generate the third expected content based on the first expected content;
[0034] The second expected content is generated based on the command code and the third expected content.
[0035] Sending a second industrial control network traffic data retrieval instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second desired retrieval content according to the second industrial control network traffic data retrieval instruction, includes:
[0036] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the command code and the first expected acquisition content according to the second industrial control network traffic data acquisition instruction;
[0037] Receive feedback industrial control network traffic data from the industrial control network traffic archive database regarding the first desired content; or,
[0038] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the command code and the third expected acquisition content according to the second industrial control network traffic data acquisition instruction;
[0039] Receive feedback industrial control network traffic data sent by the industrial control network traffic archive database for the third desired content;
[0040] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and the command code according to the second industrial control traffic data acquisition instruction;
[0041] Receive feedback industrial control traffic data sent by the industrial control network traffic archive database for the first desired content;
[0042] Receive feedback industrial control traffic data for the command code sent by the industrial control network traffic archive database;
[0043] Alternatively, a second industrial control network traffic data acquisition instruction may be sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and the command code according to the second industrial control network traffic data acquisition instruction;
[0044] Receive feedback industrial control network traffic data sent by the industrial control network traffic archive database for the third desired content;
[0045] Receive feedback industrial control traffic data for the command code sent by the industrial control network traffic archive database.
[0046] Optionally, before obtaining the first industrial control network traffic data acquisition instruction for the target industrial control network node, the method further includes:
[0047] The system acquires operator permissions, industrial control network node permissions, industrial control network traffic permissions, and traffic acquisition method permissions. The industrial control network traffic permissions include traffic usage and traffic security level, and the traffic acquisition method permissions include data transmission methods.
[0048] A traffic acquisition strategy is generated based on the operator permissions, the industrial control network node, the industrial control network traffic's own permissions, and the traffic acquisition method permissions.
[0049] Optionally, after determining the set of traffic acquisition strategies based on the target industrial control network node and the target operator's permissions, the method further includes:
[0050] If the first expected content to be obtained does not satisfy any one of the traffic acquisition strategies in the set of traffic acquisition strategies, then the first industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected content to be obtained according to the first industrial control traffic data acquisition instruction.
[0051] Optionally, after determining a first risk coefficient for each archived industrial control traffic data from a policy table used to store the first risk defense strategy, the method further includes:
[0052] Determine whether the preset strategy attribute of the first risk defense strategy is a risk defense strategy that has been constructed multiple times;
[0053] If the preset strategy attribute of the first risk defense strategy is a risk defense strategy that is constructed multiple times, the construction method of the first risk defense strategy is as follows:
[0054] A second risk coefficient is determined for each archived industrial control traffic data in the at least one archived industrial control traffic data according to the second risk defense strategy, wherein the second risk defense strategy is a historically constructed risk defense strategy.
[0055] Based on the second risk coefficient, a hierarchical clustering algorithm is performed on the at least one archived industrial control traffic data to obtain a second risk classification vector;
[0056] Determine the volume of archived industrial control flow data in each risk level indicated by the second risk classification vector;
[0057] The first risk defense strategy is obtained by adjusting the second risk defense strategy based on the traffic volume of the archived industrial control traffic data in each risk level.
[0058] Optionally, adjusting the second risk defense strategy based on the traffic volume of archived industrial control traffic data in each risk level to obtain the first risk defense strategy includes:
[0059] Based on the volume of archived industrial control traffic data in each risk level, a first target risk level is determined, and the volume of archived industrial control traffic data in the first target risk level reaches the first preset traffic warning line;
[0060] The first target risk level is assessed, and the risk coefficient interval in the second risk defense strategy is increased based on the assessment results to obtain the first risk defense strategy.
[0061] Optionally, adjusting the second risk defense strategy based on the traffic volume of archived industrial control traffic data in each risk level to obtain the first risk defense strategy includes:
[0062] Based on the volume of archived industrial control traffic data in each risk level, a second target risk level is determined. The volume of archived industrial control traffic data in the second target risk level is less than the second preset traffic warning line, and the second preset traffic warning line is less than the first preset traffic warning line.
[0063] The second target risk level is assessed, and the number of risk coefficient intervals in the second risk defense strategy is reduced based on the assessment results to obtain the first risk defense strategy.
[0064] The technical solution provided in this application includes, but is not limited to, the following beneficial effects:
[0065] By acquiring at least one archived industrial control network traffic data of the target industrial control network node; then, using K-means operation to obtain traffic service scenario vectors for multiple archived industrial control traffic data; next, determining the first risk coefficient for each archived industrial control traffic data based on the node affiliation characteristics and a first risk defense strategy; then, performing hierarchical clustering algorithm processing on each archived industrial control traffic data according to the first risk coefficient to obtain a first risk classification vector for each archived industrial control traffic data; then, constructing a risk defense mapping library for the first risk defense strategy based on the first risk classification vector of each archived industrial control traffic data and the service scenario to which it belongs in the traffic service scenario vector; finally, constructing a network attack defense mechanism for the target industrial control network node based on the risk defense mapping library. This design utilizes artificial intelligence algorithms to customize a network attack defense mechanism for the industrial control network node, thereby improving the security of the entire industrial control network.
[0066] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0067] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0068] Figure 1 The flowchart of a defense strategy determination method based on industrial control network traffic data provided in Embodiment 1 of the present invention is shown.
[0069] Figure 2 The flowchart of a traffic service scenario vector determination method provided in Embodiment 1 of the present invention is shown;
[0070] Figure 3 The flowchart of a method for determining a first risk classification vector provided in Embodiment 1 of the present invention is shown;
[0071] Figure 4 A flowchart of a target risk defense strategy storage method provided in Embodiment 1 of the present invention is shown;
[0072] Figure 5 The flowchart of a method for determining a first risk defense strategy provided in Embodiment 1 of the present invention is shown;
[0073] Figure 6 The flowchart of a first risk defense strategy adjustment method provided in Embodiment 1 of the present invention is shown;
[0074] Figure 7 A flowchart of the second method for adjusting the first risk defense strategy provided in Embodiment 1 of the present invention is shown;
[0075] Figure 8 The diagram shows a structural schematic of a defense strategy determination device based on industrial control network traffic data provided in an embodiment of the present invention. Detailed Implementation
[0076] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0077] This invention provides a method for determining a defense strategy based on industrial control network traffic data. The method clusters archived industrial control traffic data with similar business scenarios into a traffic business scenario vector based on real-world conditions. This traffic business scenario vector is then used as a standard for evaluating a first risk defense strategy. A first risk classification vector, obtained by dividing multiple archived industrial control traffic data based on the first risk defense strategy, is compared with the traffic business scenario vector. A risk defense mapping library for the first risk defense strategy is constructed based on the correlation between the first risk classification vector and the traffic business scenario vector. This risk defense mapping library reflects the correlation between the first risk classification vector and the traffic business scenario vector, thereby demonstrating the degree of conformity between the first risk classification vector and the business scenario.
[0078] In this embodiment of the invention, the server can obtain multiple archived industrial control traffic data of the target industrial control network node. The archived industrial control traffic data can be interaction samples generated by the target industrial control network node and the terminal through human-computer interaction, such as control and query related commands issued by the user through the industrial control network node.
[0079] The server can obtain traffic business scenario vectors from multiple archived industrial control traffic data. These vectors are generated by clustering archived industrial control traffic data with similar business scenarios into the same business scenario, thus reflecting real-world business scenarios. These traffic business scenario vectors can be fixed and used as a standard to determine the appropriateness of the primary risk defense strategy.
[0080] On the other hand, the server can also determine the first risk coefficient of each archived industrial control traffic data in at least one archived industrial control traffic data (multiple archived industrial control traffic data) according to the first risk defense strategy based on the node affiliation characteristics. Based on the first risk coefficient, the Agglomerative algorithm is executed on multiple archived industrial control traffic data to obtain the first risk classification vector. In other words, the first risk classification vector is divided according to the first risk defense strategy.
[0081] When using traffic service scenario vectors as the standard for evaluating the first risk defense strategy, if the first risk defense strategy is reasonably constructed and the risk definition accuracy is moderate, then the first risk classification vector, divided according to the first risk defense strategy, should conform to the actual situation. That is, the first risk classification vector should be quite similar to the labeled traffic service scenario vector. Therefore, the server can construct a risk defense mapping library for the first risk defense strategy based on the correlation between the traffic service scenario vector and the first risk classification vector. This risk defense mapping library can accurately measure the quality of the constructed risk defense strategy (e.g., whether the risk definition accuracy is reasonable). Furthermore, based on this risk defense mapping library, a risk defense strategy with reasonable risk definition accuracy can be constructed more accurately, so as to establish accurate risk characteristics of industrial control network nodes in the industrial control network under the aforementioned different service scenarios based on the finally constructed risk defense strategy.
[0082] To facilitate understanding of this application, the following is combined with... Figure 1 The flowchart illustrating a method for determining a defense strategy based on industrial control network traffic data provided in this embodiment of the invention will be described in detail below.
[0083] See Figure 1 As shown, Figure 1 The flowchart of a defense strategy determination method based on industrial control network traffic data provided in Embodiment 1 of the present invention is shown, wherein the method includes steps S101 to S106;
[0084] S101: Obtain at least one archived industrial control traffic data of the target industrial control network node.
[0085] Specifically, the node affiliation characteristics of the target industrial control network node are obtained by mining the archived industrial control traffic data of the target industrial control network node. Therefore, in this embodiment, at least one archived industrial control traffic data of the target industrial control network node can be obtained first.
[0086] Taking a query business scenario as an example, the target industrial control network node is the device used by the user to perform the query operation, and the node's affiliation characteristics are the risk characteristics of the industrial control network node. The risk characteristics of the industrial control network node in the query business scenario are mined from the historical operations performed by the user during various query operations. This can be done through a single round of historical operations or through multiple rounds of historical operations. This embodiment uses the mining of risk characteristics of industrial control network nodes through a single round of historical operations as an example, treating the single round of historical operations as archived industrial control traffic data. Therefore, in this embodiment, the server can randomly sample a batch of historical operations from the user's operation logs in the query business scenario, using these operations from the devices used by the user to perform the query operation as multiple archived industrial control traffic data for the target industrial control network node. Multiple archived industrial control traffic data of the target industrial control network node can be represented as K1 (the first archived industrial control traffic data), K2 (the second archived industrial control traffic data), K3 (the third archived industrial control traffic data), ..., K7 (the seventh archived industrial control traffic data), K8 (the eighth archived industrial control traffic data), ..., Km (the mth archived industrial control traffic data, where m is a non-zero natural number).
[0087] S102: Use the K-means clustering algorithm to perform business scenario clustering on the at least one archived industrial control traffic data to obtain a traffic business scenario vector describing the business scenario to which each of the archived industrial control traffic data belongs.
[0088] Specifically, after obtaining multiple archived industrial control traffic data sets, these data sets can be labeled. This involves categorizing the archived industrial control traffic data sets according to their actual business scenarios. Data sets with the same business scenario are grouped together, and this group can be called a business scenario. This results in a traffic business scenario vector for the multiple archived industrial control traffic data sets. This traffic business scenario vector indicates which business scenario each archived industrial control traffic data set belongs to.
[0089] Taking multiple archived industrial control traffic data as K1, K2, K3, ..., K7, K8, ..., Km as an example, the business scenarios of these multiple archived industrial control traffic data are classified. The resulting traffic business scenario vector can be in the following form: [K1, K3, K5, K7] are located in business scenario 1, [K2, K4, K6, K8] are located in business scenario 2, ..., [Km] are located in business scenario N, etc.
[0090] S103: For each of the archived industrial control traffic data, determine the first risk coefficient of the archived industrial control traffic data from the strategy table used to store the first risk defense strategy.
[0091] Specifically, the first risk defense strategy is the risk defense strategy currently being constructed and to be evaluated. The core task of node attribution characteristics (risk characteristics of industrial control network nodes) is to determine the risk coefficients for industrial control network nodes. These risk coefficients can abstract a risk system for industrial control network nodes. Each risk coefficient describes a risk situation of the node, and the various risk situations are interconnected, collectively constituting a risk system for the industrial control network nodes.
[0092] The server can determine the first risk coefficient of each archived industrial control traffic data in multiple archived industrial control traffic data based on the first risk defense strategy of node affiliation characteristics. For example, the first risk coefficient of K1, K2, K3, and K4 is <0: no risk>, the first risk coefficient of K5, K6, K7, and K8 is <1: low risk>, ..., and the first risk coefficient of Km is <2: high risk>.
[0093] It should be noted that, in one possible implementation, the first risk coefficient can be determined using a model corresponding to the first risk defense strategy for determining the risk coefficient. This model can be pre-trained; therefore, the method provided in this application embodiment can relate to machine learning in the field of artificial intelligence. Machine learning and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and teaching-based learning. A model corresponding to the first risk defense strategy for determining the risk coefficient can be trained through machine learning.
[0094] S104: Based on the first risk coefficient of each archived industrial control traffic data, perform hierarchical clustering algorithm processing on each archived industrial control traffic data to obtain the first risk classification vector of each archived industrial control traffic data, wherein the first risk classification vector is used to describe the risk level of the archived industrial control traffic data.
[0095] Specifically, after obtaining the first risk coefficient, the server can perform the Agglomerative algorithm on multiple archived industrial control traffic data based on the first risk coefficient to obtain a first risk classification vector. This first risk classification vector indicates the risk level of each archived industrial control traffic data. It is worth noting that in this embodiment of the invention, both the K-means algorithm (K-means clustering algorithm) and the Agglomerative algorithm (hierarchical clustering algorithm) are used. The reason is that although the k-means algorithm has high performance, its noise resistance is weak, while the Agglomerative algorithm has high noise resistance. Therefore, using K-means first and then Agglomerative effectively avoids further increase in noise and improves the accuracy of the overall solution.
[0096] S105: Construct a risk defense mapping library for the first risk defense strategy based on the first risk classification vector of each archived industrial control traffic data and the business scenario to which it belongs in the traffic business scenario vector.
[0097] Specifically, since the traffic business scenario vector is obtained by clustering archived industrial control traffic data with the same business scenario into one business scenario and labeling it, it conforms to the real business scenario. Therefore, the server can use the traffic business scenario vector as the standard for evaluating the first risk defense strategy. If the first risk defense strategy is constructed reasonably and the risk definition is of moderate accuracy, then the first risk classification vector divided according to the first risk defense strategy should conform to the real situation. That is, the first risk classification vector should be quite similar to the labeled traffic business scenario vector. Therefore, the server can construct a risk defense mapping library for the first risk defense strategy based on the correlation between the traffic business scenario vector and the first risk classification vector.
[0098] The risk defense mapping library for the first risk defense strategy can be considered as the accuracy of risk coefficient and risk definition. A higher correlation between the first risk classification vector and the traffic business scenario vector indicates a closer match between the first risk classification vector and the actual situation, and a more reasonable risk definition accuracy for the first risk defense strategy. This ensures that the risk definition accuracy is neither too low nor too high, preventing the risk defense strategy from becoming overly complex and lacking universality. Therefore, the risk defense mapping library for the first risk defense strategy constructed based on the correlation can accurately measure the quality of the constructed risk defense strategy, and thus, based on this risk defense mapping library, a more accurate risk defense strategy with reasonable risk definition accuracy can be constructed.
[0099] If the traffic business scenario vector is a business scenario classification label group and the first risk classification vector is a first risk level label group, then the risk defense mapping library of the first risk defense strategy can be constructed by calculating the label position association between the business scenario classification label group and the first risk level label group based on the association between the traffic business scenario vector and the first risk classification vector, and then constructing the risk defense mapping library of the first risk defense strategy based on the label position association.
[0100] As can be seen from the above technical solution, for multiple archived industrial control network traffic data of a target industrial control network node, on the one hand, the corresponding traffic service scenario vector can be obtained; on the other hand, the first risk coefficient of each archived industrial control traffic data can be determined according to the first risk defense strategy based on the node's attribution characteristics. The Agglomerative algorithm is then executed on the multiple archived industrial control traffic data based on the first risk coefficient to obtain the first risk classification vector. In other words, the first risk classification vector is divided according to the first risk defense strategy. Since the traffic service scenario vector is obtained by clustering archived industrial control traffic data with similar service scenarios into a single service scenario and labeling them, it conforms to the real service scenario. Therefore, the traffic service scenario vector can be used as a standard for evaluating the first risk defense strategy. If the first risk defense strategy is constructed reasonably and the risk definition accuracy is moderate, then the first risk classification vector divided according to the first risk defense strategy should conform to the real situation, that is, the first risk classification vector should be similar to the labeled traffic service scenario vector. Therefore, a risk defense mapping library for the first risk defense strategy can be constructed based on the correlation between the traffic service scenario vector and the first risk classification vector. In this way, the risk defense mapping library of the first risk defense strategy can reflect the correlation between the first risk classification vector and the traffic business scenario vector. The higher the correlation between the first risk classification vector and the traffic business scenario vector, the more the first risk classification vector matches the real situation, and the more reasonable the risk definition accuracy of the first risk defense strategy. Therefore, the risk defense mapping library of the first risk defense strategy can more accurately measure the quality of the constructed risk defense strategy (e.g., whether the risk definition accuracy is reasonable). Based on this risk defense mapping library, a risk defense strategy with reasonable risk definition accuracy can be constructed more accurately.
[0101] The risk defense mapping library of the first risk defense strategy is used to evaluate the effectiveness of the first risk defense strategy. In this embodiment, the risk defense strategy can be iteratively optimized based on the constructed risk defense mapping library. Next, the method for iteratively optimizing the risk defense strategy based on the constructed risk defense mapping library, as provided in this embodiment, will be introduced in conjunction with a practical application scenario. In this embodiment, a query business scenario is taken as an example. In this case, the node affiliation characteristic can be the risk characteristic of an industrial control network node. In order to establish accurate risk characteristics of industrial control network nodes in the query business scenario and to support the risk characteristics of industrial control network nodes in subsequent related businesses, the risk defense strategy can be iteratively optimized based on the constructed risk defense mapping library. This results in a risk defense strategy with risk coefficient and risk definition accuracy that conforms to the actual situation, i.e., a reasonable risk coefficient and risk definition accuracy.
[0102] In this embodiment, the method for iteratively optimizing risk defense strategies based on the constructed risk defense mapping library mainly consists of four processes: process one is data preparation, process two is risk defense strategy evaluation, process three is risk defense strategy adjustment, and process four is iterative loop, specifically including the following steps:
[0103] Step 1: Randomly sample the historical operations of the devices used to perform the query operation on the industrial control network nodes.
[0104] Step 2: Classify historical operations by business scenario to obtain traffic business scenario vectors.
[0105] Steps one and two constitute process one. The data preparation process mainly involves preparing data that can be reused in subsequent processes, such as traffic business scenario vectors and historical operations.
[0106] Step 3: For the first risk defense strategy, calculate the risk defense mapping library of the first risk defense strategy.
[0107] The first risk defense strategy is the risk defense strategy to be evaluated. The calculation method for the risk defense mapping library of the first risk defense strategy can be found in S103-S105, and will not be repeated here. The first risk defense strategy is evaluated using the obtained risk defense mapping library of the first risk defense strategy, i.e., step three is process two. If the first risk defense strategy is an initially constructed (first-time construction) risk defense strategy, then the risk defense mapping library of the first risk defense strategy is used as the standard risk defense mapping library.
[0108] Step 4: Optimize the risk defense strategy based on the risk defense mapping library of the first risk defense strategy, and determine the target risk defense strategy.
[0109] Step four is equivalent to process three, which involves adjusting the risk defense strategy based on the risk defense mapping library. The specific implementation of step four can be found in the description of the aforementioned embodiments, and will not be repeated here.
[0110] Then, the iterative loop process shown in step four begins. During each iteration, the first risk defense strategy constructed in that iteration is continuously optimized through iterative steps two and three, using the risk defense mapping library constructed above as the evaluation criterion for the quality of the iteration.
[0111] Specifically, after obtaining the risk defense mapping library of the first risk defense strategy, if the first risk defense strategy is an initially constructed (first-time) risk defense strategy, then the risk defense mapping library of the first risk defense strategy is used as the standard risk defense mapping library. If the first risk defense strategy is a risk defense strategy that has been constructed multiple times (not the first-time), the risk defense strategy is optimized based on the risk defense mapping library of the first risk defense strategy to determine the target risk defense strategy (i.e., the latest version of the risk defense strategy).
[0112] S106: Construct a network attack defense mechanism for the target industrial control network node based on the risk defense mapping library.
[0113] Specifically, in this embodiment of the invention, by constructing the risk defense mapping library, when an industrial control network node receives an external network attack, it can quickly distinguish the risk of the current network attack and the degree of its impact. This helps maintenance personnel to quickly determine a more suitable defense plan, avoiding resource waste caused by excessive operations on low-risk issues and information security problems caused by improper handling of high-risk issues.
[0114] In one feasible implementation plan, see Figure 2 As shown, Figure 2 The flowchart illustrates a method for determining a traffic service scenario vector according to Embodiment 1 of the present invention. The method involves using a K-means clustering algorithm to perform service scenario clustering processing on at least one archived industrial control traffic data to obtain a traffic service scenario vector describing the service scenario to which each archived industrial control traffic data belongs. This includes steps S201 to S202.
[0115] S201: Obtain the business scenario classification label for each of the at least one archived industrial control traffic data.
[0116] S202: After clustering each of the archived industrial control traffic data's business scenario classification labels using the K-means clustering algorithm, the business scenario classification label groups are arranged according to preset scenario weights to obtain the business scenario classification label groups, which serve as the traffic business scenario vector.
[0117] Specifically, in one possible scenario, to differentiate between different business scenarios, each business scenario can be assigned a corresponding business scenario classification label (identifier, id), with different business scenario IDs for different scenarios. Thus, when archived industrial control traffic data is clustered into a certain business scenario, the archived industrial control traffic data corresponds to the business scenario ID of that scenario, indicating which business scenario the archived industrial control traffic data belongs to. In this case, the method to obtain the traffic business scenario vector of multiple archived industrial control traffic data can be to obtain the business scenario classification label of each archived industrial control traffic data, arrange the business scenario classification labels of each archived industrial control traffic data according to a preset scenario weight to obtain a business scenario classification label group, and use the business scenario classification label group as the traffic business scenario vector.
[0118] The preset scenario weights can be the order in which the archived industrial control traffic data is arranged. If the archived industrial control traffic data are K1, K2, K3, ..., K7, K8, ..., Km, their order is as described above. K1, K3, K5, and K7 are located in business scenario 1, and the business scenario classification label for business scenario 1 is 1, then the business scenario classification label corresponding to K1, K3, K5, and K7 is 1; K2, K4, K6, and K8 are located in business scenario 2, and the business scenario classification label for business scenario 2 is 2, then the business scenario classification label corresponding to K2, K4, K6, and K8 is 2; ...; Km is located in business scenario N, and the business scenario classification label for business scenario N is N, then the business scenario classification label corresponding to Km is N. Therefore, according to the order in which the archived industrial control traffic data is arranged, the business scenario classification label group obtained by arranging the business scenario classification labels of the archived industrial control traffic data is 1, 2, 1, 2, 1, 2, 1, 2, ..., N.
[0119] It should be noted that the obtained traffic business scenario vector is labeled data. The traffic business scenario vector can be fixed and used as a standard to judge the effectiveness of the first risk defense strategy in each iteration.
[0120] It is understood that the above business scenario classification labels are only an example, and the business scenario classification labels for each business scenario can also be represented by other values. This application embodiment does not limit this.
[0121] In one feasible implementation plan, see Figure 3 As shown, Figure 3The flowchart illustrates a method for determining a first risk classification vector according to Embodiment 1 of the present invention. The method involves performing hierarchical clustering on each archived industrial control traffic data point based on a first risk coefficient to obtain a first risk classification vector for each archived industrial control traffic data point, including steps S301 to S302.
[0122] S301: Cluster the archived industrial control traffic data whose values of the first risk coefficient belong to the same preset range into the same risk level to obtain the first risk level label of each of the archived industrial control traffic data.
[0123] S302: Arrange the first risk level label of each of the archived industrial control traffic data according to the preset risk level weight to obtain the first risk level label group, and the first risk level label group is used as the first risk classification vector.
[0124] Specifically, assume that K1, K2, K3, K4 are at risk level 1, K5, K6, K7, K8 are at risk level 2, ..., and Km is at risk level K.
[0125] Similar to business scenarios, to distinguish different risk levels, a corresponding risk level label (identifier, id) can be assigned to each risk level, with different risk level ids for different risk levels. Thus, when archived industrial control traffic data is clustered into a certain risk level, the archived industrial control traffic data corresponds to a risk level id for that risk level, indicating which risk level the archived industrial control traffic data belongs to. In this case, the method for obtaining the first risk classification vector by performing the Agglomerative algorithm on multiple archived industrial control traffic data based on the first risk coefficient can be as follows: cluster archived industrial control traffic data whose first risk coefficient values belong to the same range into one risk level, obtaining a first risk level label for each archived industrial control traffic data; arrange the first risk level labels of each archived industrial control traffic data according to a preset risk level weight to obtain a first risk level label group; and use the first risk level label group as the first risk classification vector.
[0126] The preset risk level weights can be the arrangement order of the archived industrial control flow data. If the archived industrial control flow data are K1, K2, K3, ..., K7, K8, ..., Km, their arrangement order is as described above. K1, K2, K3, and K4 are located at risk level 1, and the first risk level label for risk level 1 is 1, then the first risk level label corresponding to K1, K2, K3, and K4 is 1; K5, K6, K7, and K8 are located at risk level 2, and the first risk level label for risk level 2 is 2, then the first risk level label corresponding to K5, K6, K7, and K8 is 2; ...; Km is located at risk level K, and the first risk level label for risk level K is K, then the first risk level label corresponding to Km is K. Therefore, according to the arrangement order of the archived industrial control flow data, the first risk level label group obtained by arranging the first risk level labels of the archived industrial control flow data is 1, 1, 1, 1, 2, 2, 2, 2, ..., K.
[0127] It is understood that the above-mentioned first risk level label is only an example, and the first risk level label for each risk level can also be represented by other values, which is not limited in this application embodiment.
[0128] In one feasible implementation plan, see Figure 4 As shown, Figure 4 The flowchart illustrates a target risk defense strategy storage method provided in Embodiment 1 of the present invention. After constructing a risk defense mapping library for the first risk defense strategy based on the first risk classification vector of each archived industrial control traffic data and the respective business scenario to which it belongs in the traffic business scenario vector, the method further includes steps S401 to S403:
[0129] S401: Determine whether the first risk defense success rate of the risk defense mapping library of the first risk defense strategy is higher than the second risk defense success rate of the risk defense mapping library of the second risk defense strategy, wherein the second risk defense strategy is a historically constructed risk defense strategy.
[0130] S402: If the success rate of the first risk defense is higher than the success rate of the second risk defense, the first risk defense strategy is stored as the target risk defense strategy.
[0131] S403: If the success rate of the first risk defense is not higher than the success rate of the second risk defense, the second risk defense strategy is stored as the target risk defense strategy.
[0132] Specifically, the risk defense strategy is optimized based on the risk defense mapping library of the first risk defense strategy. The target risk defense strategy can be determined by testing the risk defense mapping library of the first risk defense strategy and the risk defense mapping library of the second risk defense strategy based on the node affiliation characteristics. The second risk defense strategy is the risk defense strategy constructed previously. Then, the target risk defense strategy is determined based on the test results.
[0133] If the test results indicate that the success rate of the first risk defense strategy is higher than that of the second risk defense strategy, the first risk defense strategy will be used as the target risk defense strategy; if the test results indicate that the success rate of the first risk defense strategy is lower than that of the second risk defense strategy, the second risk defense strategy will be used as the target risk defense strategy.
[0134] For example, the risk defense mapping library for the first risk defense strategy is the accuracy of the risk coefficient and risk definition of the first risk defense strategy, and the risk defense mapping library for the second risk defense strategy is the accuracy of the risk coefficient and risk definition of the second risk defense strategy. If the test results show that the accuracy of the risk coefficient and risk definition of the first risk defense strategy is higher than that of the second risk defense strategy, it indicates that the risk defense success rate of the first risk defense strategy is higher than that of the second risk defense strategy, meaning that there is a gain effect multiple times. Therefore, the first risk defense strategy is chosen as the target risk defense strategy. If the test results show that the accuracy of the risk coefficient and risk definition of the first risk defense strategy is lower than that of the second risk defense strategy, it indicates that the risk defense success rate of the first risk defense strategy is lower than that of the second risk defense strategy, meaning that there is no gain effect multiple times. Therefore, the second risk defense strategy (the risk defense strategy of the previous version, i.e., the risk defense strategy built previously) is chosen as the target risk defense strategy.
[0135] This application continuously optimizes the risk defense strategy through the above methods, using the accuracy of the risk coefficient and risk definition as the evaluation criterion for the quality of the risk defense mapping library, and continuously optimizes the risk defense strategy based on the node affiliation characteristics.
[0136] In a feasible implementation plan, since industrial control network traffic data inherently possesses a certain degree of confidentiality and cannot be disclosed arbitrarily, the following methods can be used to improve the security of industrial control network traffic data: obtaining at least one archived industrial control network traffic data of the target industrial control network node includes:
[0137] Obtain a first industrial control network traffic data acquisition instruction for a target industrial control network node, wherein the first industrial control network traffic data acquisition instruction includes a first expected acquisition content and operator identity information, and the operator identity information is used to indicate the target operator's permissions.
[0138] Specifically, in this embodiment, a first industrial control network traffic data acquisition instruction for a target industrial control network node is received from a traffic acquisition party. This instruction encapsulates a first desired acquisition content and operator identity information. The desired acquisition content carries node information corresponding to the target industrial control network node. Based on the operator identity information, the traffic acquisition party can be identified, thereby determining the target operator permissions corresponding to that party. For example, visitor permissions (only able to view basic information), operator permissions (able to view and manipulate basic information), and administrator permissions (able to view and manipulate confidential information).
[0139] A set of traffic acquisition strategies is determined based on the target industrial control network node and the target operator's permissions. The set of traffic acquisition strategies corresponds to the target industrial control network node, and the set of traffic acquisition strategies includes at least one traffic acquisition strategy. Each traffic acquisition strategy includes the correspondence between the industrial control network traffic's own permissions and the traffic acquisition method permissions.
[0140] Specifically, the set of traffic acquisition strategies can be determined based on the target industrial control network node and the target operator's permissions. That is, the set of traffic acquisition strategies is applicable to the target operator's permissions, and the set of traffic acquisition strategies is a set of strategies for acquiring traffic from the target industrial control network node.
[0141] After the first industrial control network traffic data acquisition command is input from an external source, it is parsed to obtain the first expected acquisition content. Following preprocessing and basic validity checks of this expected content, the system analyzes the possible matching strategies for the traffic acquisition command based on its content (industrial control network nodes, conditions, and requested traffic content, etc.). This results in a set of traffic acquisition strategies, which includes at least one strategy. These strategies may include allowing the acquisition of all traffic, allowing the acquisition of a portion of traffic, or allowing or partially acquiring traffic under specific conditions. Therefore, an industrial control network traffic data acquisition command may have one or more strategies.
[0142] Therefore, we can first determine the set of traffic acquisition strategies through analysis, then analyze each strategy within that set to determine the permissible traffic acquisition for the first desired content. Next, we formulate an execution plan based on the set of traffic acquisition strategies, review the desired content, and prepare for execution. When a pending traffic acquisition strategy appears, reviewing and executing the reviewed content is a cyclical process until each of the pending strategies has a definite result (i.e., acquire or not acquire). If a pending strategy is re-matched, the review and execution of the reviewed content continue. After all acquisition strategies have been executed, the data results are returned to the traffic acquisition party.
[0143] More specifically, taking the first industrial control network traffic data acquisition command for a target industrial control network node as an example, after parsing the first industrial control network traffic data acquisition command, the first expected acquisition content is obtained. This first expected acquisition content includes the specific traffic purpose, which may include querying, controlling, or modifying. Therefore, based on the target industrial control network node and the corresponding target operator permissions, a set of acquisition traffic strategies corresponding to the traffic purpose of the first expected acquisition content is obtained. Each acquisition traffic strategy set includes the industrial control network traffic's own permissions and its corresponding traffic acquisition method permissions. The industrial control network traffic's own permissions include the traffic purpose and the traffic security level. For example, if the first expected acquisition content is used for "querying" traffic purposes, then all acquisition traffic strategies in the acquisition traffic strategy set belong to the "query" traffic purpose. Therefore, it is then determined whether the first expected acquisition content acquires the "traffic security level" within the "industrial control network traffic's own permissions".
[0144] If the first expected content to be obtained satisfies the industrial control network traffic permissions included in the target traffic acquisition strategy, then the second expected content to be obtained is obtained according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, wherein the target traffic acquisition strategy belongs to the traffic acquisition strategies included in the set of traffic acquisition strategies.
[0145] Specifically, in this embodiment, it is necessary to detect the matching relationship between the first expected content to be obtained and the set of traffic acquisition strategies. Assuming that the set of traffic acquisition strategies includes N traffic acquisition strategies, N matching results are generated based on the first expected content to be obtained and the traffic acquisition strategies. For the successfully matched traffic acquisition strategy, it is the target traffic acquisition strategy corresponding to the first expected content to be obtained. In practical applications, the first expected content to be obtained can satisfy the industrial control network traffic self-permissions included by at least one target traffic acquisition strategy. For ease of explanation, this application will take obtaining the industrial control network traffic self-permissions included by any target traffic acquisition strategy as an example.
[0146] The following example illustrates how to detect "traffic security level." We will use a target industrial control network node with a first desired content acquisition instruction and the traffic purpose being "query" as an example. When the traffic purpose is "query," the corresponding industrial control traffic can be determined to have a certain traffic security level. The traffic security level can be determined by the initiator of the traffic when it is generated. For example, when generating industrial control network traffic corresponding to a query instruction for basic device information in the industrial control network, its traffic security level can be set to level 1, indicating a lower security level. When generating industrial control network traffic corresponding to a query instruction for the underlying data of core nodes in the industrial control network, its traffic security level can be set to level 3, indicating a higher security level and not easily leaked. In this embodiment of the invention, the above-mentioned traffic level setting values and basis are only examples and are not limited here.
[0147] A second industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second expected acquisition content according to the second industrial control network traffic data acquisition instruction, wherein the second industrial control network traffic data acquisition instruction includes the second expected acquisition content, and the second expected acquisition content includes the at least one archived industrial control network traffic data.
[0148] Specifically, in this embodiment, after generating the second expected content, the second expected content can be encapsulated in a second industrial control network traffic data acquisition instruction. Alternatively, operator identity information can be encapsulated together with the second expected content in the second industrial control network traffic data acquisition instruction. Then, the second industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database. The industrial control network traffic archive database executes the second expected content according to the second industrial control network traffic data acquisition instruction, and finally obtains feedback industrial control network traffic data. In this embodiment, the feedback industrial control network traffic data can be the industrial control network traffic data that the user wants to obtain for testing, i.e., multiple archived industrial control network traffic data.
[0149] First, a first industrial control network (ICS) traffic data acquisition instruction is obtained for the target ICS network node. Based on this instruction, a set of traffic acquisition strategies is determined according to the target ICS network node and the target operator's permissions. If the first desired acquisition content satisfies the ICS network traffic's own permissions included in the target traffic acquisition strategy, then the second desired acquisition content is acquired based on the first desired acquisition content and the traffic acquisition method permissions included in the target traffic acquisition strategy. Finally, a second ICS traffic data acquisition instruction is sent to the ICS network traffic archive database, causing the database to execute the second desired acquisition content according to this instruction. Through this method, the same target ICS network node can acquire different sets of traffic acquisition strategies under different operator permissions; that is, the basis for determining the traffic acquisition strategy set includes operator permissions. Similarly, the same target operator permissions can acquire different sets of traffic acquisition strategies on different ICS network nodes; that is, the basis for determining the traffic acquisition strategy set includes the ICS network node itself. The same desired acquisition content for the same target ICS network node can acquire different traffic acquisition method permissions based on different ICS network traffic's own permissions. Therefore, this application can meet the differentiated needs of operator permissions, making it easier and more flexible for operators to obtain traffic from industrial control network nodes.
[0150] In a feasible implementation, a configuration strategy is provided. Through this strategy, different strategies can be configured based on the target operator permissions corresponding to the traffic acquisition party. Settings can be configured from multiple dimensions, including operator permissions, industrial control network nodes, traffic purpose, traffic security level, and data transmission method, thereby improving the feasibility and operability of the solution. Specifically, the step of acquiring the second desired content based on the first desired content and the traffic acquisition method permissions included in the target traffic acquisition strategy includes:
[0151] If the first expected content to be obtained corresponds to a low-risk traffic use, then the traffic extraction instruction corresponding to the target industrial control network node is determined based on the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy.
[0152] The second expected content is generated based on the traffic extraction instruction and the first expected content.
[0153] If the first expected content to be obtained corresponds to a high-risk traffic purpose, then according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, the command code corresponding to the first expected content to be obtained is generated.
[0154] Generate the second desired content based on the command code and the first desired content; or,
[0155] If the first expected content to be obtained corresponds to a high-risk traffic purpose, then according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, the command code corresponding to the first expected content to be obtained is generated.
[0156] Generate the third expected content based on the first expected content;
[0157] The second expected content is generated based on the command code and the third expected content.
[0158] Sending a second industrial control network traffic data retrieval instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second desired retrieval content according to the second industrial control network traffic data retrieval instruction, includes:
[0159] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the command code and the first expected acquisition content according to the second industrial control network traffic data acquisition instruction;
[0160] Receive feedback industrial control network traffic data from the industrial control network traffic archive database regarding the first desired content; or,
[0161] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the command code and the third expected acquisition content according to the second industrial control network traffic data acquisition instruction;
[0162] Receive feedback industrial control network traffic data sent by the industrial control network traffic archive database for the third desired content;
[0163] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and the command code according to the second industrial control traffic data acquisition instruction;
[0164] Receive feedback industrial control traffic data sent by the industrial control network traffic archive database for the first desired content;
[0165] Receive feedback industrial control traffic data for the command code sent by the industrial control network traffic archive database;
[0166] Alternatively, a second industrial control network traffic data acquisition instruction may be sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and the command code according to the second industrial control network traffic data acquisition instruction;
[0167] Receive feedback industrial control network traffic data sent by the industrial control network traffic archive database for the third desired content;
[0168] Receive feedback industrial control traffic data for the command code sent by the industrial control network traffic archive database.
[0169] Specifically, this embodiment of the invention provides a method for simultaneously executing multiple expected acquisition contents. When sending a second industrial control network traffic data acquisition command, considering the logical relationship and function between the command code and the first expected acquisition content (or the third expected acquisition content), the command code and the first expected acquisition content (or the third expected acquisition content) can be executed simultaneously. Specifically, in response to the second industrial control network traffic data acquisition command, the industrial control network traffic archive database first executes the first expected acquisition content (or the third expected acquisition content), and then executes the command code after executing the first or third expected acquisition content, to obtain the industrial control traffic data as feedback from the second industrial control traffic data acquisition command.
[0170] Sending a second industrial control network traffic data retrieval instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second expected content to be retrieved according to the second industrial control network traffic data retrieval instruction, specifically including the following steps:
[0171] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and command code according to the second industrial control network traffic data acquisition instruction;
[0172] Receive industrial control network traffic data from the archived database for the first desired content;
[0173] Receive feedback industrial control network traffic data for command codes sent from the industrial control network traffic archive database;
[0174] Alternatively, a second industrial control network traffic data retrieval instruction may be sent to the industrial control network traffic archive database, causing the industrial control network traffic archive database to execute the second desired retrieval content according to the second industrial control network traffic data retrieval instruction, including:
[0175] Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and command code according to the second industrial control network traffic data acquisition instruction;
[0176] Receive industrial control network traffic data from the archived database of industrial control network traffic in response to the content that a third party expects to obtain;
[0177] Receive industrial control network traffic data corresponding to command codes from the industrial control network traffic archive database.
[0178] Specifically, the traffic acquisition method in this application will be described below from the perspective of industrial control network traffic archive database. One embodiment of the traffic acquisition method in this application includes the following steps:
[0179] Step 1: Receive the second industrial control flow data acquisition command;
[0180] In this embodiment, a first industrial control network (ICN) traffic data acquisition instruction sent by a traffic acquisition party for a target ICN network node is received. This instruction encapsulates a first desired acquisition content and operator identity information. The desired acquisition content carries node information corresponding to the target ICN network node, which is a device within an ICN network operated by a user. Based on the operator identity information, the traffic acquisition party can be identified, thereby determining the target operator's permissions.
[0181] A set of traffic acquisition strategies can be determined based on the target industrial control network node and the target operator's permissions. This means the set of traffic acquisition strategies applies to the target operator's permissions and is specifically designed for acquiring traffic from the target industrial control network node. After the first industrial control network traffic acquisition instruction is received from the data access layer of the data infrastructure, it is parsed to obtain the first expected acquisition content. Following preprocessing and basic validity checks of this content, the system analyzes the possible matching strategies for the traffic acquisition instruction based on its content (industrial control network node, conditions, and requested data content, etc.), thus obtaining a set of traffic acquisition strategies. This set includes at least one traffic acquisition strategy. A traffic acquisition strategy may result in a definite outcome (e.g., acquiring all traffic, acquiring a portion of traffic, etc.) or an indefinite outcome (e.g., allowing partial traffic acquisition under specific conditions). For indefinite outcomes, it may be necessary to determine whether to acquire traffic during subsequent execution phases or during the post-execution data fusion phase. Therefore, a single industrial control network traffic acquisition instruction may have one or more outcome sets.
[0182] It is necessary to detect whether the first expected content can match the set of traffic acquisition strategies. Assuming that the set of traffic acquisition strategies includes N traffic acquisition strategies, N matching results are generated based on the first expected content and the traffic acquisition strategies. For the successfully matched traffic acquisition strategy, it is the target traffic acquisition strategy corresponding to the first expected content. In practical applications, the first expected content can satisfy the industrial control network traffic self-permissions included in at least one target traffic acquisition strategy. For ease of explanation, this application will take obtaining the industrial control network traffic self-permissions included in any target traffic acquisition strategy as an example.
[0183] After generating the second expected content, this content can be encapsulated in a second industrial control network traffic data acquisition instruction. Alternatively, operator identification information can be encapsulated together with the second expected content in the instruction. Then, the second industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, which receives the instruction.
[0184] It should be noted that the logic of the industrial control network traffic archiving database is deployed on a server, which can be a standalone server or a cloud server; no specific limitation is made here.
[0185] Step 2: Execute the second expected content to be acquired according to the second industrial control flow data acquisition instruction;
[0186] In this embodiment, the industrial control network traffic archive database executes the second expected acquisition content according to the second industrial control traffic data acquisition instruction. Specifically, the industrial control network traffic archive database can parse the second traffic acquisition to obtain operator identity information and the second expected acquisition content. Therefore, the industrial control network traffic archive database can execute the second expected acquisition content, which includes performing specific traffic acquisition operations on the target industrial control network node.
[0187] Step 3: Obtain feedback industrial control traffic data for the second desired content;
[0188] In this embodiment, based on step two, the industrial control network traffic archive database determines the industrial control traffic required in the second expected content and uses it as feedback industrial control traffic data.
[0189] Step 4: Send feedback industrial control traffic data to the traffic acquisition party;
[0190] In this embodiment, the industrial control network traffic archive database can determine the traffic acquisition party based on the operator's identity information, and then send feedback industrial control traffic data to the traffic acquisition party, that is, multiple archived industrial control traffic data, which is not limited here.
[0191] In one feasible implementation, before obtaining the first industrial control network traffic data acquisition instruction for the target industrial control network node, the method further includes:
[0192] The system acquires operator permissions, industrial control network node permissions, industrial control network traffic permissions, and traffic acquisition method permissions. The industrial control network traffic permissions include traffic usage and traffic security level, and the traffic acquisition method permissions include data transmission methods.
[0193] A traffic acquisition strategy is generated based on the operator permissions, the industrial control network node, the industrial control network traffic's own permissions, and the traffic acquisition method permissions.
[0194] Specifically, different policies can be configured based on the target operator permissions corresponding to the traffic acquisition party. Settings can be made from multiple dimensions such as operator permissions, industrial control network nodes, traffic purpose, traffic security level, and data transmission method, thereby improving the feasibility and operability of the solution.
[0195] In a feasible implementation, after determining the set of traffic acquisition policies based on the target industrial control network node and the target operator permissions, the method further includes:
[0196] If the first expected content to be obtained does not satisfy any one of the traffic acquisition strategies in the set of traffic acquisition strategies, then the first industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected content to be obtained according to the first industrial control traffic data acquisition instruction.
[0197] Specifically, if the first expected content to be obtained does not satisfy any of the traffic acquisition strategies in the traffic acquisition strategy set, a first industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected content to be obtained according to the first industrial control traffic data acquisition instruction.
[0198] Using the above method, if it is detected that the first expected content to be obtained does not satisfy any traffic acquisition strategy in the set of traffic acquisition strategies, then it is not necessary to provide differentiated data for the target operator's permissions, and the smooth operation can be terminated directly. It should be understood that, in this embodiment of the invention, the first expected content to be obtained is used to determine whether the traffic acquisition operation is executable, and then the second expected content to be obtained is used to obtain the industrial control network traffic that the user wants to obtain for building the risk defense mapping library.
[0199] In one feasible implementation plan, see Figure 5 As shown, Figure 5The flowchart of a method for determining a first risk defense strategy provided in Embodiment 1 of the present invention is shown. In this method, after determining the first risk coefficient of each archived industrial control traffic data from the strategy table used to store the first risk defense strategy, it is determined whether the preset strategy attribute of the first risk defense strategy is a risk defense strategy that has been constructed multiple times.
[0200] If the preset strategy attribute of the first risk defense strategy is a risk defense strategy that is constructed multiple times, the construction method of the first risk defense strategy is as follows: steps S501 to S504:
[0201] S501: Determine the second risk coefficient for each archived industrial control traffic data in the at least one archived industrial control traffic data according to the second risk defense strategy, wherein the second risk defense strategy is a historically constructed risk defense strategy;
[0202] S502: Perform a hierarchical clustering algorithm on the at least one archived industrial control traffic data according to the second risk coefficient to obtain a second risk classification vector;
[0203] S503: Determine the volume of archived industrial control flow data in each risk level indicated by the second risk classification vector;
[0204] S504: The first risk defense strategy is obtained by adjusting the second risk defense strategy according to the traffic volume of the archived industrial control traffic data in each risk level.
[0205] Specifically, it should be noted that in the embodiments of this application, the first risk defense strategy can be obtained by adjusting a risk defense strategy built in a previous iteration, such as the second risk defense strategy. If the first risk defense strategy is a risk defense strategy built multiple times, the first risk defense strategy can be constructed by determining the second risk coefficient of each archived industrial control traffic data in multiple archived industrial control traffic data according to the second risk defense strategy, where the second risk defense strategy is the risk defense strategy built in the previous iteration. Then, the Agglomerative algorithm is executed on the multiple archived industrial control traffic data according to the second risk coefficient to obtain the second risk classification vector. The size of archived industrial control system (ICS) traffic data within each risk level indicated by the second risk classification vector is determined. A larger volume of archived ICS traffic data within a risk level indicates a higher risk level, potentially including archived ICS traffic data that shouldn't be classified into that level. This suggests a lower accuracy in the risk coefficient definition of the second risk defense strategy, requiring adjustments to improve the accuracy and thus reduce the risk level. Conversely, a smaller volume indicates higher accuracy, requiring adjustments to reduce the accuracy and thus expand the risk level. Therefore, the second risk defense strategy can be adjusted based on the volume of archived ICS traffic data within each risk level to obtain the first risk defense strategy.
[0206] In one feasible implementation plan, see Figure 6 As shown, Figure 6 The flowchart illustrates a method for adjusting a first risk defense strategy according to Embodiment 1 of the present invention. The method involves adjusting the second risk defense strategy based on the traffic volume of archived industrial control traffic data in each risk level to obtain the first risk defense strategy, and includes steps S601 to S602:
[0207] S601: Determine the first target risk level based on the volume of archived industrial control traffic data in each risk level, where the volume of archived industrial control traffic data in the first target risk level reaches the first preset traffic warning line.
[0208] S602: Assess the first target risk level, and increase the risk coefficient interval in the second risk defense strategy based on the assessment results to obtain the first risk defense strategy.
[0209] Specifically, when adjusting the second risk defense strategy to obtain the first risk defense strategy based on the volume of archived industrial control traffic data in each risk level, a first target risk level can be determined based on the volume of archived industrial control traffic data in each risk level. If the volume of archived industrial control traffic data in the first target risk level reaches the first preset traffic warning line, then the first target risk level is considered a larger risk level. The first target risk level is then evaluated, and the risk coefficient interval in the second risk defense strategy is increased based on the evaluation results to obtain the first risk defense strategy. This allows for targeted reduction of larger risk levels when classifying risk levels based on the first risk defense strategy.
[0210] In one feasible implementation plan, see Figure 7 As shown, Figure 7 The flowchart of the second method for adjusting the first risk defense strategy provided in Embodiment 1 of the present invention is shown. The step of adjusting the second risk defense strategy according to the traffic volume of the archived industrial control traffic data in each risk level to obtain the first risk defense strategy includes steps S701 to S702:
[0211] S701: Determine the second target risk level based on the volume of archived industrial control traffic data in each risk level. The volume of archived industrial control traffic data in the second target risk level is less than the second preset traffic warning line, and the second preset traffic warning line is less than the first preset traffic warning line.
[0212] S702: Assess the second target risk level, and reduce the number of risk coefficient intervals in the second risk defense strategy based on the assessment results to obtain the first risk defense strategy.
[0213] Specifically, when adjusting the second risk defense strategy to obtain the first risk defense strategy based on the volume of archived industrial control traffic data in each risk level, a second target risk level can also be determined based on the volume of archived industrial control traffic data in each risk level. In the second target risk level, the volume of archived industrial control traffic data is less than the second preset traffic warning line, and the second preset traffic warning line is less than the first preset traffic warning line; that is, the second target risk level is a risk level that is too small. Then, the second target risk level is evaluated, and based on the evaluation results, the number of risk coefficient intervals in the second risk defense strategy is reduced to obtain the first risk defense strategy. This allows for the targeted expansion of excessively small risk levels when classifying risk levels based on the first risk defense strategy.
[0214] This invention also provides a device for determining defense strategies for industrial control network traffic data, see [link to relevant documentation]. Figure 8 As shown, Figure 8This diagram illustrates a structural schematic of a defense strategy determination device based on industrial control network traffic data, provided in an embodiment of the present invention. The device includes:
[0215] The industrial control traffic data acquisition module 801 is used to acquire at least one archived industrial control traffic data of the target industrial control network node;
[0216] The traffic service scenario vector determination module 802 is used to perform service scenario clustering processing on the at least one archived industrial control traffic data using the K-means clustering algorithm to obtain a traffic service scenario vector describing the service scenario to which each of the archived industrial control traffic data belongs.
[0217] The first risk coefficient determination module 803 is used to determine the first risk coefficient of each archived industrial control traffic data from the strategy table used to store the first risk defense strategy.
[0218] The first risk classification vector determination module 804 is used to perform hierarchical clustering algorithm processing on each of the archived industrial control traffic data according to the first risk coefficient of each of the archived industrial control traffic data to obtain the first risk classification vector of each of the archived industrial control traffic data, wherein the first risk classification vector is used to describe the risk level of the archived industrial control traffic data.
[0219] The risk defense mapping library construction module 805 is used to construct the risk defense mapping library of the first risk defense strategy based on the first risk classification vector of each archived industrial control traffic data and the business scenario to which each of the traffic business scenario vectors belongs.
[0220] The network attack defense mechanism construction module 806 is used to construct the network attack defense mechanism of the target industrial control network node based on the risk defense mapping library.
[0221] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the system and apparatus described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0222] The device for determining the defense strategy of industrial control network traffic data provided in this embodiment of the invention can be specific hardware on the device or software or firmware installed on the device. The implementation principle and technical effects of the device provided in this embodiment of the invention are the same as those in the foregoing method embodiments. For the sake of brevity, any parts not mentioned in the device embodiments can be referred to the corresponding content in the foregoing method embodiments. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can all be referred to the corresponding processes in the above method embodiments, and will not be repeated here.
[0223] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and method can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0224] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0225] In addition, the functional units in the embodiments provided by the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0226] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0227] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first", "second", "third", etc. are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0228] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. All should be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for determining defense strategies based on industrial control network traffic data, characterized in that, The method includes: Obtain at least one archived industrial control network traffic data of the target industrial control network node; The K-means clustering algorithm is used to perform business scenario clustering on the at least one archived industrial control traffic data to obtain a traffic business scenario vector describing the business scenario to which each archived industrial control traffic data belongs; For each of the archived industrial control traffic data, a first risk coefficient for the archived industrial control traffic data is determined from the strategy table used to store the first risk defense strategy; Based on the first risk coefficient of each archived industrial control traffic data, a hierarchical clustering algorithm is performed on each archived industrial control traffic data to obtain a first risk classification vector for each archived industrial control traffic data, wherein the first risk classification vector is used to describe the risk level of the archived industrial control traffic data. Based on the first risk classification vector of each archived industrial control traffic data and the business scenario to which it belongs in the traffic business scenario vector, a risk defense mapping library for the first risk defense strategy is constructed. A network attack defense mechanism for the target industrial control network node is constructed based on the aforementioned risk defense mapping library.
2. The method according to claim 1, characterized in that, The K-means clustering algorithm is used to perform business scenario clustering on the at least one archived industrial control traffic data to obtain a traffic business scenario vector describing the business scenario to which each archived industrial control traffic data belongs, including: Obtain the business scenario classification label for each of the at least one archived industrial control traffic data; After clustering each of the archived industrial control traffic data's business scenario classification labels using the K-means clustering algorithm, the business scenario classification label groups are arranged according to preset scenario weights, and the business scenario classification label groups serve as the traffic business scenario vector.
3. The method according to claim 2, characterized in that, The step of performing hierarchical clustering on each archived industrial control traffic data based on a first risk coefficient to obtain a first risk classification vector for each archived industrial control traffic data includes: The archived industrial control traffic data whose values of the first risk coefficient belong to the same preset range are clustered into the same risk level to obtain the first risk level label of each archived industrial control traffic data; The first risk level label of each archived industrial control traffic data is arranged according to the preset risk level weight to obtain the first risk level label group, and the first risk level label group is used as the first risk classification vector.
4. The method according to claim 1, characterized in that, After constructing a risk defense mapping library for the first risk defense strategy based on the first risk classification vector of each archived industrial control traffic data and the business scenario to which it belongs in the traffic business scenario vector, the method further includes: Determine whether the success rate of the first risk defense in the risk defense mapping library of the first risk defense strategy is higher than the success rate of the second risk defense in the risk defense mapping library of the second risk defense strategy, wherein the second risk defense strategy is a historically constructed risk defense strategy; If the success rate of the first risk defense is higher than the success rate of the second risk defense, the first risk defense strategy will be stored as the target risk defense strategy. If the success rate of the first risk defense is not higher than the success rate of the second risk defense, the second risk defense strategy will be stored as the target risk defense strategy.
5. The method according to claim 1, characterized in that, The acquisition of at least one archived industrial control network traffic data of the target industrial control network node includes: Obtain a first industrial control network traffic data acquisition instruction for a target industrial control network node, wherein the first industrial control network traffic data acquisition instruction includes a first expected acquisition content and operator identity information, and the operator identity information is used to indicate the target operator's permissions; A set of traffic acquisition strategies is determined based on the target industrial control network node and the target operator's permissions. The set of traffic acquisition strategies corresponds to the target industrial control network node, and the set of traffic acquisition strategies includes at least one traffic acquisition strategy. Each traffic acquisition strategy includes the correspondence between the industrial control network traffic's own permissions and the traffic acquisition method permissions. If the first expected content satisfies the industrial control network traffic permissions included in the target traffic acquisition strategy, then the second expected content is acquired based on the first expected content and the traffic acquisition method permissions included in the target traffic acquisition strategy, wherein the target traffic acquisition strategy belongs to the traffic acquisition strategies included in the traffic acquisition strategy set. A second industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second expected acquisition content according to the second industrial control network traffic data acquisition instruction, wherein the second industrial control network traffic data acquisition instruction includes the second expected acquisition content, and the second expected acquisition content includes the at least one archived industrial control network traffic data; The step of obtaining the second desired content based on the first desired content and the traffic acquisition method permissions included in the target traffic acquisition strategy includes: If the first expected content to be obtained corresponds to a low-risk traffic use, then the traffic extraction instruction corresponding to the target industrial control network node is determined based on the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy. The second expected content is generated based on the traffic extraction instruction and the first expected content. If the first expected content to be obtained corresponds to a high-risk traffic purpose, then according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, the command code corresponding to the first expected content to be obtained is generated. Generate the second desired content based on the command code and the first desired content; or, If the first expected content to be obtained corresponds to a high-risk traffic purpose, then according to the first expected content to be obtained and the traffic acquisition method permissions included in the target traffic acquisition strategy, the command code corresponding to the first expected content to be obtained is generated. Generate the third expected content based on the first expected content; The second expected content is generated based on the command code and the third expected content. Sending a second industrial control network traffic data retrieval instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the second desired retrieval content according to the second industrial control network traffic data retrieval instruction, includes: Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the command code and the first expected acquisition content according to the second industrial control network traffic data acquisition instruction; Receive feedback industrial control network traffic data from the industrial control network traffic archive database regarding the first desired content; or, Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the command code and the third expected acquisition content according to the second industrial control network traffic data acquisition instruction; Receive feedback industrial control network traffic data sent by the industrial control network traffic archive database for the third desired content; Send a second industrial control network traffic data acquisition instruction to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected acquisition content and the command code according to the second industrial control traffic data acquisition instruction; Receive feedback industrial control traffic data sent by the industrial control network traffic archive database for the first desired content; Receive feedback industrial control traffic data for the command code sent by the industrial control network traffic archive database; Alternatively, a second industrial control network traffic data acquisition instruction may be sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the third desired acquisition content and the command code according to the second industrial control network traffic data acquisition instruction; Receive feedback industrial control network traffic data sent by the industrial control network traffic archive database for the third desired content; Receive feedback industrial control traffic data for the command code sent by the industrial control network traffic archive database.
6. The method according to claim 5, characterized in that, Before obtaining the first industrial control network traffic data acquisition instruction for the target industrial control network node, the method further includes: The system acquires operator permissions, industrial control network node permissions, industrial control network traffic permissions, and traffic acquisition method permissions. The industrial control network traffic permissions include traffic usage and traffic security level, and the traffic acquisition method permissions include data transmission methods. A traffic acquisition strategy is generated based on the operator permissions, the industrial control network node, the industrial control network traffic's own permissions, and the traffic acquisition method permissions.
7. The method according to claim 5, characterized in that, After determining the set of traffic acquisition strategies based on the target industrial control network node and the target operator's permissions, the method further includes: If the first expected content to be obtained does not satisfy any one of the traffic acquisition strategies in the set of traffic acquisition strategies, then the first industrial control network traffic data acquisition instruction is sent to the industrial control network traffic archive database, so that the industrial control network traffic archive database executes the first expected content to be obtained according to the first industrial control traffic data acquisition instruction.
8. The method according to claim 1, characterized in that, After determining the first risk coefficient of each archived industrial control traffic data from the policy table used to store the first risk defense strategy, the method further includes: Determine whether the preset strategy attribute of the first risk defense strategy is a risk defense strategy that has been constructed multiple times; If the preset strategy attribute of the first risk defense strategy is a risk defense strategy that is constructed multiple times, the construction method of the first risk defense strategy is as follows: A second risk coefficient is determined for each archived industrial control traffic data in the at least one archived industrial control traffic data according to the second risk defense strategy, wherein the second risk defense strategy is a historically constructed risk defense strategy. Based on the second risk coefficient, a hierarchical clustering algorithm is performed on the at least one archived industrial control traffic data to obtain a second risk classification vector; Determine the volume of archived industrial control flow data in each risk level indicated by the second risk classification vector; The first risk defense strategy is obtained by adjusting the second risk defense strategy based on the traffic volume of the archived industrial control traffic data in each risk level.
9. The method according to claim 8, characterized in that, The step of adjusting the second risk defense strategy based on the traffic volume of the archived industrial control traffic data in each risk level to obtain the first risk defense strategy includes: Based on the volume of archived industrial control traffic data in each risk level, a first target risk level is determined, and the volume of archived industrial control traffic data in the first target risk level reaches the first preset traffic warning line; The first target risk level is assessed, and the risk coefficient interval in the second risk defense strategy is increased based on the assessment results to obtain the first risk defense strategy.
10. The method according to claim 8 or 9, characterized in that, The step of adjusting the second risk defense strategy based on the traffic volume of the archived industrial control traffic data in each risk level to obtain the first risk defense strategy includes: Based on the volume of archived industrial control traffic data in each risk level, a second target risk level is determined. The volume of archived industrial control traffic data in the second target risk level is less than the second preset traffic warning line, and the second preset traffic warning line is less than the first preset traffic warning line. The second target risk level is assessed, and the number of risk coefficient intervals in the second risk defense strategy is reduced based on the assessment results to obtain the first risk defense strategy.