An intrusion detection method and system for an industrial control system
By adding noise in industrial control systems and estimating the state vector in real time using Kalman filtering algorithm, the problem of intrusion detection in the prior art is solved, and more efficient and accurate intrusion detection is achieved.
Patent Information
- Application Number
- CN202211471382.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-11-23
AI Technical Summary
The existing industrial control system intrusion detection methods are difficult to detect physical-level system abnormalities, machine learning methods consume a lot of resources, and the false alarm rate and missed alarm rate based on the probability model are high, and most detection devices are deployed at the remote end, making it difficult to perceive changes in the physical state of the control process as soon as possible.
By determining the system matrix, control matrix and other parameters of the industrial control system, obtaining the original control signal and sensing data, adding noise to the control signal, using the Kalman filtering algorithm to estimate the status vector in real time, calculate the detection variable, and determine whether the preset threshold value has exceeded to determine whether the system has been invaded.
It improves the accuracy and efficiency of intrusion detection of industrial control systems, reduces the false alarm rate and missed alarm rate, and can sense and respond to system intrusion more quickly.
Smart Images

Figure CN115913724B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intrusion detection, and particularly to an intrusion detection method and system for an industrial control system. Background Art
[0002] In the existing intrusion detection methods for industrial systems, the detection method of analyzing communication messages is difficult to detect system anomalies at the physical level. The machine learning method usually has a high operation cost, consuming a large amount of time and computing resources. The method based on the probability model often has a high false alarm rate and a high missed alarm rate. All of the above methods are passive detections, that is, all detection information comes from the system itself, and no information and commands are actively input into the system. Moreover, almost all current detection devices are deployed in remote SCADA or independent computer systems or embedded devices, which require an independent system to complete, and are far from the industrial site, vulnerable to deception, and it is difficult to perceive the change of the physical state of the control process in the first time when being attacked, resulting in a low detection rate. Summary of the Invention
[0003] The purpose of the present invention is to provide an intrusion detection method and system for an industrial control system, which improves the detection rate of intrusion into the industrial control system.
[0004] To achieve the above purpose, the present invention provides the following solutions:
[0005] An intrusion detection method for an industrial control system, the method includes:
[0006] Determine the system matrix, control matrix, output matrix, observation noise covariance matrix, steady-state state covariance matrix, and steady-state Kalman gain of the target system; the target system is the industrial control system to be detected;
[0007] Obtain the original control signal at the k-1 moment, the sensing data at the k-1 moment, and the sensing data at the k moment in the target system; the original control signal is the signal of the controller in the target system, and the sensing data is the data detected by the sensor in the target system; k>2;
[0008] Add noise to the original control signal at the k-1 moment to obtain the noise-added control signal at the k-1 moment;
[0009] Determine the prior estimate of the state vector at the k moment according to the system matrix, the control matrix, the noise-added control signal at the k-1 moment, and the posterior estimate of the state vector at the k-1 moment; the posterior estimate of the state vector at the k-1 moment is determined according to the output matrix, the steady-state Kalman gain, the sensing data at the k-1 moment, and the prior estimate of the state vector at the k-2 moment;
[0010] Determine a detection variable based on the prior estimate of the state vector at time k, the output matrix, the sensing data at time k, the steady-state state covariance matrix, and the observation noise covariance matrix;
[0011] Determine whether the detection variable is greater than a preset threshold;
[0012] If so, the target system is invaded at time k;
[0013] If not, the target system is not invaded at time k.
[0014] Optionally, the determining of the detection variable based on the prior estimate of the state vector at time k, the output matrix, the sensing data at time k, the steady-state state covariance matrix, and the observation noise covariance matrix specifically includes:
[0015] Calculate the estimated residual vector at time k according to the prior estimate of the state vector at time k, the output matrix, and the sensing data at time k;
[0016] Determine the detection variable according to the estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0017] Optionally, the determining of the detection variable according to the estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix specifically includes:
[0018] Use a filtering method to filter each component of the estimated residual vector at time k;
[0019] Determine the detection variable according to the filtered estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0020] Optionally, the filtering method includes: a limit filtering method and a recursive median filtering method.
[0021] An intrusion detection system for an industrial control system, the system includes:
[0022] An initial parameter determination module, configured to determine the system matrix, the control matrix, the output matrix, the observation noise covariance matrix, the steady-state state covariance matrix, and the steady-state Kalman gain of the target system; the target system is the industrial control system to be detected;
[0023] A signal acquisition module, configured to acquire the original control signal at time k - 1, the sensing data at time k - 1, and the sensing data at time k in the target system; the original control signal is the signal of the controller in the target system, and the sensing data is the data detected by the sensor in the target system; k > 2;
[0024] An active noise addition module, configured to add noise to the original control signal at the (k - 1)th moment to obtain a noise - added control signal at the (k - 1)th moment;
[0025] A prior estimate determination module, configured to determine a prior estimate of the state vector at the kth moment according to the system matrix, the control matrix, the noise - added control signal at the (k - 1)th moment, and the posterior estimate of the state vector at the (k - 1)th moment; the posterior estimate of the state vector at the (k - 1)th moment is determined according to the output matrix, the steady - state Kalman gain, the sensing data at the (k - 1)th moment, and the prior estimate of the state vector at the (k - 2)th moment;
[0026] A detection variable determination module, configured to determine a detection variable according to the prior estimate of the state vector at the kth moment, the output matrix, the sensing data at the kth moment, the steady - state state covariance matrix, and the observation noise covariance matrix;
[0027] A judgment module, configured to judge whether the detection variable is greater than a preset threshold;
[0028] A first result output module, configured to, if so, indicate that the target system is invaded at the kth moment;
[0029] A second result output module, configured to, if not, indicate that the target system is not invaded at the kth moment.
[0030] Optionally, the detection variable determination module specifically includes:
[0031] An estimated residual vector calculation sub - module, configured to calculate an estimated residual vector at the kth moment according to the prior estimate of the state vector at the kth moment, the output matrix, and the sensing data at the kth moment;
[0032] A detection variable determination sub - module, configured to determine a detection variable according to the estimated residual vector at the kth moment, the output matrix, the steady - state state covariance matrix, and the observation noise covariance matrix.
[0033] Optionally, the detection variable determination sub - module specifically includes:
[0034] A filtering unit, configured to filter each component of the estimated residual vector at the kth moment by using a filtering method;
[0035] A detection variable determination unit, configured to determine a detection variable according to the filtered estimated residual vector at the kth moment, the output matrix, the steady - state state covariance matrix, and the observation noise covariance matrix.
[0036] Optionally, the filtering method in the filtering unit includes: a limit - amplitude filtering method and a recursive median filtering method.
[0037] According to the specific embodiments provided by the present invention, the following technical effects are disclosed by the present invention:
[0038] The present invention discloses an intrusion detection method and system for an industrial control system. After obtaining the original control signal and sensing data in the industrial control system, noise is actively added to the original control signal, and the prior estimate of the state vector is determined in real time by using the sensing data and the noise-added control signal, so as to determine the detection variable, and it is determined in real time whether the industrial control system is invaded according to the detection variable. Compared with the existing passive detection methods, the present invention adopts an active noise addition method, which improves the detection rate of intrusion into the industrial control system. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.
[0040] Figure 1 It is a schematic flow chart of the intrusion detection method for the industrial control system provided by the embodiment of the present invention;
[0041] Figure 2 It is a schematic diagram of the intrusion detection framework;
[0042] Figure 3 It is a schematic structural diagram of the intrusion detection system for the industrial control system provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0044] The purpose of the present invention is to provide an intrusion detection method and system for an industrial control system, aiming to improve the detection rate of intrusion into the industrial control system.
[0045] In order to make the above objects, features and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.
[0046] Figure 1 It is a schematic flow chart of the intrusion detection method for the industrial control system provided by the embodiment of the present invention. As Figure 1As shown in the figure, the intrusion detection method for the industrial control system in this embodiment
[0047] Step 101: Determine the system matrix, control matrix, output matrix, observation noise covariance matrix, steady-state state covariance matrix, and steady-state Kalman gain of the target system; the target system is the industrial control system to be detected.
[0048] Step 102: Obtain the original control signal at time k-1, the sensing data at time k-1, and the sensing data at time k in the target system; the original control signal is the signal of the controller in the target system, and the sensing data is the data detected by the sensor in the target system; k>2.
[0049] Step 103: Add noise to the original control signal at time k-1 to obtain the noise-added control signal at time k-1.
[0050] Step 104: Determine the prior estimate of the state vector at time k according to the system matrix, control matrix, the noise-added control signal at time k-1, and the posterior estimate of the state vector at time k-1; the posterior estimate of the state vector at time k-1 is determined according to the output matrix, steady-state Kalman gain, the sensing data at time k-1, and the prior estimate of the state vector at time k-2.
[0051] Step 105: Determine the detection variable according to the prior estimate of the state vector at time k, the output matrix, the sensing data at time k, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0052] Step 106: Determine whether the detection variable is greater than a preset threshold.
[0053] Step 107: If so, the target system is invaded at time k.
[0054] Step 108: If not, the target system is not invaded at time k.
[0055] As an alternative implementation, step 105 specifically includes:
[0056] Calculate the estimated residual vector at time k according to the prior estimate of the state vector at time k, the output matrix, and the sensing data at time k.
[0057] Determine the detection variable according to the estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0058] As an alternative implementation, determining the detection variable according to the estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix specifically includes:
[0059] Using a filtering method, each component of the estimated residual vector at time k is filtered.
[0060] Determine the detection variable according to the estimated residual vector, output matrix, steady-state state covariance matrix, and observation noise covariance matrix after filtering at time k.
[0061] As an alternative implementation, the filtering method includes: a clipping filtering method and a recursive median filtering method.
[0062] Specifically, as Figure 2 shown, an intrusion detection framework is established according to the above method. A system designed based on this framework can be deployed in the controller of an industrial control system to achieve real-time intrusion detection. The framework includes:
[0063] (1) Active noise addition module: Add random noise to the control signal generated by the controller (this controller is an existing controller in the industrial control system to be detected, mainly referring to the control program) through the following active noise addition strategy:
[0064] At time i, the noise-added control signal is u' i = u i + Δu i , where u i is the original control signal generated by the control program, and the random noise Δu i satisfies the Gaussian distribution Δu i ~ N(0, αV i ), and α is the noise addition factor. w a is the time window, and α and w a are set manually in combination with the specific control system. The variance of the random Gaussian noise is positively correlated with the square of the control signal within the time window, which can play a role in adaptively adjusting the noise size and avoid overly affecting the control performance or failing to promote the detection effect.
[0065] (2) State estimation module: Use a linear dynamic system model to update the state variables of the system. When the control system is working in a stable state, collect sensor data y and control signal u for a period of time, convert them into analog quantities, subtract the steady-state value of the system operating point, and then use the N4SID method for the collected sensor data y and control signal u. Manually determine the sampling time interval and the state space dimension, and the corresponding state space model (state space equation) can be obtained for offline identification. By changing the selection of the output variable and the dimension of the state space, a set of state space equations with better fitting degrees can be obtained.
[0066] Based on the coefficient matrices A, B, C, the system noise covariance matrix Q, and the observation noise covariance matrix R obtained from the state space equation with better goodness of fit, the steady-state state variable covariance matrix P and the steady-state Kalman gain K are calculated offline by iterative calculation using the following Kalman filter formulas (according to the following three iterations:
[0067] The prior estimate of the covariance matrix of the system state at time f: P f|f-1 = AP f-1|f-1 A T + Q;
[0068] The updated Kalman gain at time f: K f = P f|f-1 C T (CP f|f-1 C T + R) -1 ;
[0069] The posterior estimate of the system covariance matrix at time f: P f|f = P f|f-1 - K f CP f|f-1 ).
[0070] Among them, P f-1|f-1 is the posterior estimate of the system covariance matrix at time f - 1, and T is the transpose. The noise-added control signal u' generated by the active noise addition module is used as the input, and the state variables of the system (the system to be detected, that is, the controlled object) are updated in real time using the Kalman filter.
[0071] According to the iterative formula of the steady-state Kalman filter at time k: where A, B, C are the system matrices, is the prior estimate of the state vector at time k, is the posterior estimate of the state vector at time k, y k is the observation vector at time k (i.e., the sensor data at time k), is the posterior estimate of the state vector at time k - 1, u' k-1 is the noise-added control signal at time k - 1, and thus the output
[0072] (3) Residual calculation and filtering module: According to the state estimation result of the Kalman filter and the sensor data at time k, the estimated residual vector of the Kalman filter at time k can be calculated: In order to eliminate the influence brought by the non-linear error of the system, it is necessary to perform z kEach component is filtered, and two filtering methods are mainly used: limiting filtering and recursive median filtering. Limiting filtering is mainly used to eliminate the pulse signal generated by the model error. If the difference between the two signals is greater than the set value, the average value of the past few times is used to replace the latter value. Recursive median filtering is used to eliminate false alarms caused by errors. The data in a time window is averaged after removing the maximum and minimum values and taken as the value at the current moment, thereby obtaining the processed residual vector z' k .
[0073] (4) Anomaly detection module: Obtain the processed residual vector z' k , using χ 2 The detector calculates the detection variable Among them, w m is the time window of the recursive median filter (the time window of the recursive median filter used in the residual calculation and filtering module), p = (CPC T +R) -1 , p is an intermediate parameter for the convenience of calculation and has no practical significance. k If it exceeds the threshold δ, the system is considered to be under attack or abnormal at time k; otherwise, the system is considered to be normal at time k.
[0074] Figure 3 The schematic diagram of the intrusion detection system structure of the industrial control system provided by the embodiment of the present invention is as follows. Figure 3 As shown, the intrusion detection system of the industrial control system in this embodiment includes:
[0075] The initial parameter determination module 201 is used to determine the system matrix, control matrix, output matrix, observation noise covariance matrix, steady-state state covariance matrix and steady-state Kalman gain of the target system; the target system is the industrial control system to be detected.
[0076] The signal acquisition module 202 is used to obtain the original control signal at time k-1, the sensor data at time k-1 and the sensor data at time k in the target system; the original control signal is the signal of the controller in the target system, and the sensor data is the data detected by the sensor in the target system; k>2.
[0077] The active noise adding module 203 is used to add noise to the original control signal at time k-1 to obtain the control signal at time k-1 after the noise is added.
[0078] A prior estimate determination module 204, configured to determine a prior estimate of the state vector at time k according to the system matrix, the control matrix, the control signal at time k-1 with added noise, and the posterior estimate of the state vector at time k-1; the posterior estimate of the state vector at time k-1 is determined according to the output matrix, the steady-state Kalman gain, the sensing data at time k-1, and the prior estimate of the state vector at time k-2.
[0079] A detection variable determination module 205, configured to determine a detection variable according to the prior estimate of the state vector at time k, the output matrix, the sensing data at time k, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0080] A judgment module 206, configured to judge whether the detection variable is greater than a preset threshold.
[0081] A first result output module 207, configured to, if so, determine that the target system is invaded at time k.
[0082] A second result output module 208, configured to, if not, determine that the target system is not invaded at time k.
[0083] As an alternative implementation, the detection variable determination module 205 specifically includes:
[0084] An estimated residual vector calculation sub-module, configured to calculate an estimated residual vector at time k according to the prior estimate of the state vector at time k, the output matrix, and the sensing data at time k.
[0085] A detection variable determination sub-module, configured to determine a detection variable according to the estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0086] As an alternative implementation, the detection variable determination sub-module specifically includes:
[0087] A filtering unit, configured to filter each component of the estimated residual vector at time k by using a filtering method.
[0088] A detection variable determination unit, configured to determine a detection variable according to the filtered estimated residual vector at time k, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
[0089] As an alternative implementation, the filtering method in the filtering unit includes: a clipping filtering method and a recursive median filtering method.
[0090] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0091] In this article, specific examples are used to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the method of the present invention and its core idea. At the same time, for those of ordinary skill in the art, based on the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. An intrusion detection method for an industrial control system, characterized in that, The method includes: Determining a system matrix, a control matrix, an output matrix, an observation noise covariance matrix, a steady-state state covariance matrix, and a steady-state Kalman gain of a target system; the target system is an industrial control system to be detected; Obtaining an original control signal at the (k - 1)th moment, sensing data at the (k - 1)th moment, and sensing data at the kth moment in the target system; the original control signal is the signal of the controller in the target system, and the sensing data is the data detected by the sensor in the target system; k > 2; Adding noise to the original control signal at the (k - 1)th moment to obtain a noise-added control signal at the (k - 1)th moment; Determining a prior estimate of the state vector at the kth moment according to the system matrix, the control matrix, the noise-added control signal at the (k - 1)th moment, and the posterior estimate of the state vector at the (k - 1)th moment; the posterior estimate of the state vector at the (k - 1)th moment is determined according to the output matrix, the steady-state Kalman gain, the sensing data at the (k - 1)th moment, and the prior estimate of the state vector at the (k - 2)th moment; Determining a detection variable according to the prior estimate of the state vector at the kth moment, the output matrix, the sensing data at the kth moment, the steady-state state covariance matrix, and the observation noise covariance matrix; Judging whether the detection variable is greater than a preset threshold; If so, the target system is invaded at the kth moment; If not, the target system is not invaded at the kth moment.
2. The intrusion detection method for an industrial control system according to claim 1, characterized in that The determining the detection variable according to the prior estimate of the state vector at the kth moment, the output matrix, the sensing data at the kth moment, the steady-state state covariance matrix, and the observation noise covariance matrix specifically includes: Calculating an estimated residual vector at the kth moment according to the prior estimate of the state vector at the kth moment, the output matrix, and the sensing data at the kth moment; Determining the detection variable according to the estimated residual vector at the kth moment, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
3. The intrusion detection method for an industrial control system according to claim 2, characterized in that, The determining the detection variable according to the estimated residual vector at the kth moment, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix specifically includes: Filtering each component of the estimated residual vector at the kth moment by using a filtering method; Determining the detection variable according to the filtered estimated residual vector at the kth moment, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
4. The intrusion detection method for an industrial control system according to claim 3, characterized in that, The filtering method includes: a limit filtering method and a recursive median filtering method.
5. An intrusion detection system for an industrial control system, characterized in that, The system includes: An initial parameter determination module, configured to determine a system matrix, a control matrix, an output matrix, an observation noise covariance matrix, a steady-state state covariance matrix, and a steady-state Kalman gain of a target system; the target system is an industrial control system to be detected; A signal acquisition module, configured to obtain an original control signal at the (k - 1)th moment, sensing data at the (k - 1)th moment, and sensing data at the kth moment in the target system; the original control signal is the signal of the controller in the target system, and the sensing data is the data detected by the sensor in the target system; k > 2; An active noise addition module, which is used to add noise to the original control signal at the (k - 1)th moment to obtain the noise-added control signal at the (k - 1)th moment; A prior estimate determination module, which is used to determine the prior estimate of the state vector at the kth moment according to the system matrix, the control matrix, the noise-added control signal at the (k - 1)th moment, and the posterior estimate of the state vector at the (k - 1)th moment; the posterior estimate of the state vector at the (k - 1)th moment is determined according to the output matrix, the steady-state Kalman gain, the sensing data at the (k - 1)th moment, and the prior estimate of the state vector at the (k - 2)th moment; A detection variable determination module, which is used to determine a detection variable according to the prior estimate of the state vector at the kth moment, the output matrix, the sensing data at the kth moment, the steady-state state covariance matrix, and the observation noise covariance matrix; A judgment module, which is used to judge whether the detection variable is greater than a preset threshold; A first result output module, which is used to, if so, indicate that the target system is invaded at the kth moment; A second result output module, which is used to, if not, indicate that the target system is not invaded at the kth moment.
6. The intrusion detection system for an industrial control system according to claim 5, characterized in that, The detection variable determination module specifically includes: An estimated residual vector calculation sub-module, which is used to calculate the estimated residual vector at the kth moment according to the prior estimate of the state vector at the kth moment, the output matrix, and the sensing data at the kth moment; A detection variable determination sub-module, which is used to determine a detection variable according to the estimated residual vector at the kth moment, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
7. The intrusion detection system for an industrial control system according to claim 6, wherein The detection variable determination sub-module specifically includes: A filtering unit, which is used to filter each component of the estimated residual vector at the kth moment by using a filtering method; A detection variable determination unit, which is used to determine a detection variable according to the filtered estimated residual vector at the kth moment, the output matrix, the steady-state state covariance matrix, and the observation noise covariance matrix.
8. The intrusion detection system for an industrial control system according to claim 7, wherein The filtering methods in the filtering unit include: a limit filtering method and a recursive median filtering method.
Citation Information
Patent Citations
Scene-based hybrid invasion detection method and system
CN102546638A
Intrusion detection method based on noise network and reinforcement learning
CN113392878A