Industrial protocol topology generation method, device and system based on industrial firewall

By connecting to the industrial firewall in the industrial control network environment, deeply analyzing traffic messages and drawing the topological nodes and communication relationships of industrial control equipment, the problem of difficult to intuitively express the communication protocol relationship of industrial control equipment in the existing technology is solved, and efficient graphical visual display is achieved.

CN115883384BActive Publication Date: 2025-05-13BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211593273.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-13
Publication Date
2025-05-13
Estimated Expiration
2042-12-13

AI Technical Summary

Technical Problem

The prior art is difficult to intuitively express the communication protocol relationship between industrial control equipment, and the traditional method is inefficient, so it is necessary to manually draw the communication relationship between industrial control equipment.

Method used

By connecting to the industrial firewall in the industrial control network environment, the traffic packets are deeply analyzed, the five-tuple information, industrial protocol name and function code data are obtained, and the topological nodes and communication relationships of the industrial control equipment are used.

Benefits of technology

It realizes the display of the communication direction between industrial control equipment, the communication direction, communication between equipment and detailed functional code data in a graphical visual manner, which is more visual and efficient than traditional plain text list data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883384B_ABST
    Figure CN115883384B_ABST
Patent Text Reader

Abstract

The present invention discloses an industrial protocol topology generation method, device and system based on an industrial firewall, which belongs to the field of industrial control networks and includes the following steps: connecting the industrial firewall to the industrial control network environment; deeply analyzing the flow message, obtaining data and storing it in a database in a table; the industrial firewall system draws the basic industrial equipment topology node according to the source IP, MAC and destination IP, MAC in the data stored in the database; the industrial control equipment nodes are connected by communication, and the connection follows the session direction; the communication function code list data is drawn according to the communication protocol between the industrial control equipment; the associated specific communication function code instruction data stored in the database is queried according to the communication protocol between the industrial control equipment and the source destination IP or MAC, and sorted, and then the specific function code data transmitted between the industrial control equipment is displayed. Compared with the traditional pure text list data, the present invention has a more visual sense.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial control networks, and more specifically, to an industrial protocol topology generation method, device and system based on an industrial firewall. Background Art

[0002] In an industrial network environment, there are many industrial control devices used for industrial production. To facilitate the management of the devices, the traditional method is often to record the information of each device, or to describe the communication relationship between the industrial control device client and the server in a list form. However, this method cannot intuitively express the communication protocol relationship between industrial control devices, and it does not have the ability to describe the detailed function codes sent by the industrial protocol for real-time communication between industrial control devices. In some industrial control network environments, the communication relationship between industrial control devices even needs to be drawn manually, which is extremely inefficient. Summary of the invention

[0003] The purpose of the present invention is to overcome the shortcomings of the prior art and provide an industrial protocol topology generation method, device and system based on an industrial firewall, which can realize the overall industrial control equipment, the communication direction between devices, the industrial protocol of the communication and the detailed function code of the communication in a graphical visualization manner, which is more visual than traditional pure text list data.

[0004] The object of the present invention is achieved through the following solutions:

[0005] A method for generating an industrial protocol topology based on an industrial firewall comprises the following steps:

[0006] S1, connect the industrial firewall to the industrial control network environment;

[0007] S2, deeply analyzes the traffic packets passing through the industrial firewall, obtains data and stores it in the database in tables to serve as the basic data for drawing the protocol topology;

[0008] S3, the industrial firewall system draws the basic industrial equipment topology nodes based on the source IP, MAC and destination IP, MAC in the data stored in the database;

[0009] S4, communicate with the industrial control equipment nodes, and the connection follows the session direction;

[0010] S5, drawing communication function code list data according to the communication protocol between industrial control devices;

[0011] S6, query the associated specific communication function code instruction data stored in the database according to the communication protocol between the industrial control devices and the source destination IP or MAC, sort them, and then display the specific function code data transmitted between the industrial control devices.

[0012] Furthermore, in step S1, a sub-step is also included: after the industrial firewall is connected to the industrial control network environment, a corresponding whitelist access control policy is configured.

[0013] Furthermore, in step S2, the data acquisition includes the sub-steps of acquiring quintuple information of the flow message, the name of the industrial protocol of the communication and detailed industrial protocol communication function code data.

[0014] Furthermore, in step S3, the unique identifier of the node is the IP or MAC address of the industrial control device.

[0015] Further, in step S4, the industrial control equipment nodes are connected for communication, and the connection follows the session direction, including sub-steps: the direction from the source IP to the destination IP, the connection has an arrow to indicate the session direction, and the name of the industrial protocol of the communication is marked on the connection.

[0016] Further, in step S5, communication function code list data is drawn for viewing communication details between industrial control protocols in the topology.

[0017] Furthermore, in step S6, the sorting is specifically sorting by time dimension.

[0018] Furthermore, in step S6, the display is specifically a paged display in the form of a pop-up list.

[0019] An industrial protocol topology generation device based on an industrial firewall comprises a memory, a processor and a computer program stored in the memory and executable by the processor, wherein the processor implements any of the above methods when executing the program.

[0020] An industrial protocol topology generation system based on an industrial firewall comprises the industrial protocol topology generation device based on the industrial firewall as described above.

[0021] The beneficial effects of the present invention include:

[0022] The technical solution of the embodiment of the present invention utilizes the message deep detection advantage of the industrial firewall to automatically analyze the message to form a whitelist communication relationship between industrial control devices. It can not only draw the traditional session topology, but also form detailed industrial control protocol function code data to draw the industrial protocol topology.

[0023] The technical solution of the embodiment of the present invention can realize the visualization of the overall industrial control equipment, the communication direction between the equipment, the industrial protocol of the communication and the detailed function code of the communication in a graphical way, which is more visual than the traditional pure text list data. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0025] Figure 1 A flowchart of the steps of a method for generating an industrial protocol topology based on an industrial firewall system according to an embodiment of the present invention;

[0026] Figure 2 A topology simulation diagram drawn for an industrial protocol topology generation method based on an industrial firewall system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0027] All features disclosed in all embodiments in this specification, or steps in all methods or processes implicitly disclosed, except for mutually exclusive features and / or steps, can be combined and / or expanded or replaced in any manner.

[0028] In order to solve the technical problems in the background, the technical solution of the embodiment of the present invention provides a technical solution for generating industrial protocol topology based on an industrial firewall system. The specific solution of the present invention is described as follows:

[0029] Step 1: Connect the industrial firewall to the industrial control network environment and configure the corresponding whitelist access control policy;

[0030] Step 2: Perform in-depth analysis on the traffic packets passing through the industrial firewall, obtain the five-tuple information of the traffic packets, the name of the industrial protocol for communication, and the detailed industrial protocol communication function code and other data, and store them in the database in separate tables as the basic data for drawing the protocol topology;

[0031] Step 3, the industrial firewall system draws the basic industrial equipment topology node based on the source IP, MAC and destination IP, MAC in the five-tuple data stored in the database. The unique identifier of the node is the IP or MAC address of the industrial control device;

[0032] Step 4: Connect the industrial control equipment nodes to the communication line. The line follows the session direction, that is, the direction from the source IP to the destination IP. The line has an arrow to indicate the session direction, and the name of the industrial protocol for communication is marked on the line.

[0033] Step 5: Draw detailed communication function code list data according to the communication protocol between industrial control devices, which is used to view the communication details between industrial control protocols in the topology;

[0034] Step 6, query the database for the associated specific communication function code instruction data stored according to the communication protocol between the industrial control devices and the source destination IP or MAC, sort them by time dimension, and display the specific function code data transmitted between the industrial control devices in a pop-up list.

[0035] The above technical solutions of the embodiments of the present invention can realize the visualization of the overall industrial control equipment, the communication direction between the equipment, the industrial protocol of the communication and the detailed function code of the communication in a graphical way, which is more visual than the traditional pure text list data.

[0036] In a further embodiment, in combination Figure 1 and Figure 2 The industrial protocol topology generation method based on the industrial firewall system provided by the technical solution of the embodiment of the present invention is described in detail. Figure 1 As shown, the specific steps include:

[0037] 1) The industrial firewall is connected to the industrial control network environment and the corresponding whitelist access control policy is configured;

[0038] 2) Perform in-depth analysis on the traffic messages passing through the industrial firewall, obtain the five-tuple information of the traffic message, the name of the industrial protocol for communication, and the detailed industrial protocol communication function code and other data, and store them in the database in separate tables, which will serve as the basic data for drawing the protocol topology;

[0039] 3) The industrial firewall system draws the basic industrial equipment topology node based on the source IP, MAC and destination IP, MAC in the five-tuple data stored in the database. The unique identifier of the node is the IP or MAC address of the industrial control device;

[0040] 4) Connect the industrial control equipment nodes to the communication line. The connection follows the session direction, that is, the direction from the source IP to the destination IP. The connection line has an arrow to indicate the session direction, and the name of the industrial protocol for communication is marked on the connection line;

[0041] 5) Draw detailed communication function code list data according to the communication protocol between industrial control equipment, which is used to view the communication details between industrial control protocols in the topology;

[0042] 6) According to the communication protocol between the industrial control devices and the source and destination IP or MAC, the database is queried for the associated specific communication function code instruction data stored therein, and the data is sorted by time dimension, and the specific function code data transmitted between the industrial control devices is displayed in a pop-up list in pages;

[0043] The above technical solution can realize the visualization of the overall industrial control equipment, the communication direction between devices, the industrial protocol of communication and the detailed function code of communication in a graphical way, which is more visual than the traditional pure text list data.

[0044] like Figure 2 As shown, it is an example diagram of the industrial protocol topology drawn by the technical solution of the embodiment of the present invention, wherein:

[0045] 1) Draw two example nodes of the industrial control equipment client and server in the industrial firewall system according to the five-tuple data parsed from the message;

[0046] 2) Connect the session according to the source and destination directions of the devices. The direction of the connection arrow indicates the communication direction between the devices, and the name of the protocol for communication between the devices is marked on the connection line;

[0047] 3) Add events on directional connection lines to query the detailed function code instructions for communication between devices. The detailed function code data is displayed in a list format, supporting paging query, and detailing all communication instructions and communication time between devices.

[0048] The technical solution of the embodiment of the present invention utilizes the message deep detection advantage of the industrial firewall to automatically analyze the message to form a whitelist communication relationship between industrial control devices. It can not only draw the traditional session topology, but also form detailed industrial control protocol function code data to draw the industrial protocol topology.

[0049] It should be noted that within the scope of protection defined in the claims of the present invention, the following embodiments can be combined and / or expanded or replaced in any logical way from the above specific implementation methods, such as disclosed technical principles, disclosed technical features or implicitly disclosed technical features.

[0050] Example 1

[0051] A method for generating an industrial protocol topology based on an industrial firewall comprises the following steps:

[0052] S1, connect the industrial firewall to the industrial control network environment;

[0053] S2, deeply analyzes the traffic packets passing through the industrial firewall, obtains data and stores it in the database in tables to serve as the basic data for drawing the protocol topology;

[0054] S3, the industrial firewall system draws the basic industrial equipment topology nodes based on the source IP, MAC and destination IP, MAC in the data stored in the database;

[0055] S4, connect the industrial control equipment nodes to the communication line, and the connection follows the session direction;

[0056] S5, drawing communication function code list data according to the communication protocol between industrial control devices;

[0057] S6, query the associated specific communication function code instruction data stored in the database according to the communication protocol between the industrial control devices and the source destination IP or MAC, sort them, and then display the specific function code data transmitted between the industrial control devices.

[0058] Example 2

[0059] Based on Example 1, step S1 further includes a sub-step: after the industrial firewall is connected to the industrial control network environment, a corresponding whitelist access control policy is configured.

[0060] Example 3

[0061] On the basis of Example 1, in step S2, the data acquisition includes sub-steps of acquiring quintuple information of the flow message, the name of the industrial protocol of the communication and detailed industrial protocol communication function code data.

[0062] Example 4

[0063] Based on Example 1, in step S3, the unique identifier of the node is the IP or MAC address of the industrial control device.

[0064] Example 5

[0065] Based on Example 1, in step S4, the industrial control equipment nodes are connected for communication, and the connection follows the session direction, including sub-steps: the direction from source IP to destination IP, the connection has an arrow to indicate the session direction, and the name of the industrial protocol of the communication is marked on the connection.

[0066] Example 6

[0067] Based on Example 1, in step S5, communication function code list data is drawn for viewing communication details between industrial control protocols in the topology.

[0068] Example 7

[0069] Based on Example 1, in step S6, the sorting is specifically sorting by time dimension.

[0070] Example 8

[0071] Based on the embodiment 1, in step S6, the display is specifically a page display in the form of a pop-up list.

[0072] Example 9

[0073] An industrial protocol topology generation device based on an industrial firewall includes a memory, a processor, and a computer program stored in the memory and executable by the processor. When the processor executes the program, a method as described in any one of Examples 1 to 8 is implemented.

[0074] Example 10

[0075] An industrial protocol topology generation system based on an industrial firewall includes an industrial protocol topology generation device based on an industrial firewall as described in Example 9.

[0076] The units involved in the embodiments of the present invention may be implemented by software or hardware, and the units described may also be arranged in a processor. The names of these units do not, in some cases, limit the units themselves.

[0077] According to one aspect of an embodiment of the present invention, a computer program product or a computer program is provided, the computer program product or the computer program includes a computer instruction, and the computer instruction is stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the method provided in the above various optional implementations.

[0078] As another aspect, an embodiment of the present invention further provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the method described in the above embodiment.

[0079] The parts not involved in the present invention are the same as the prior art or can be implemented by using the prior art.

[0080] The above technical solution is only one implementation mode of the present invention. For those skilled in the art, it is easy to make various types of improvements or modifications based on the application methods and principles disclosed in the present invention, and it is not limited to the method described in the above specific implementation mode of the present invention. Therefore, the method described above is only preferred and does not have a restrictive meaning.

[0081] In addition to the above examples, those skilled in the art may obtain other embodiments based on the above disclosure or by using the knowledge or technology in the relevant field to make changes. The features of each embodiment may be interchangeable or replaced. The changes and modifications made by those skilled in the art do not depart from the spirit and scope of the present invention and should be within the scope of protection of the claims attached to the present invention.

Claims

1. A method for generating industrial protocol topology based on industrial firewall, characterized in that: The following steps are involved: S1, connect the industrial firewall to the industrial control network environment; S2, deeply analyzes the traffic packets passing through the industrial firewall, obtains data and stores it in the database in tables to serve as the basic data for drawing the protocol topology; In step S2, the data acquisition includes the sub-steps of: acquiring the five-tuple information of the flow message, the name of the industrial protocol of the communication, and the detailed industrial protocol communication function code data by parsing; S3, the industrial firewall system draws the basic industrial equipment topology nodes based on the source IP, MAC and destination IP, MAC in the data stored in the database; S4, communicate with the industrial control equipment nodes, and the connection follows the session direction; In step S4, the industrial control device nodes are connected for communication, and the connection follows the direction of the session, including sub-steps: the direction from the source IP to the destination IP, the connection has an arrow to indicate the direction of the session, and the name of the industrial protocol of the communication is marked on the connection; S5, drawing communication function code list data according to the communication protocol between industrial control devices; S6, query the associated specific communication function code instruction data stored in the database according to the communication protocol between the industrial control devices and the source destination IP or MAC, sort them, and then display the specific function code data transmitted between the industrial control devices.

2. The method for generating industrial protocol topology based on industrial firewall according to claim 1, characterized in that: In step S1, a sub-step is also included: after the industrial firewall is connected to the industrial control network environment, a corresponding whitelist access control policy is configured.

3. The method for generating industrial protocol topology based on industrial firewall according to claim 1, characterized in that: In step S3, the unique identifier of the node is the IP or MAC address of the industrial control device.

4. The method for generating industrial protocol topology based on industrial firewall according to claim 1, characterized in that: In step S5, the communication function code list data is drawn for viewing the communication details between the industrial control protocols in the topology.

5. The method for generating industrial protocol topology based on industrial firewall according to claim 1, characterized in that: In step S6, the sorting is specifically sorting by time dimension.

6. The method for generating industrial protocol topology based on industrial firewall according to claim 1, characterized in that: In step S6, the display is specifically a paged display in the form of a pop-up list.

7. An industrial protocol topology generation device based on an industrial firewall, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method according to any one of claims 1 to 6 when executing the program.

8. An industrial protocol topology generation system based on an industrial firewall, characterized in that: It includes an industrial protocol topology generating device based on an industrial firewall as described in claim 7.

Citation Information

Patent Citations

  • Industrial control network security protection monitoring system

    CN109474607A

  • Industrial control network access rule construction method and training system

    CN110011973A