Industrial control network intrusion detection system and method

Through an intrusion detection system based on parameter prediction and state verification, the vulnerability of industrial control networks to attacks is solved, the detection and location of data tampering are achieved, and the safety of production processes and equipment is ensured.

CN116094774BActive Publication Date: 2025-09-30TANGSHAN ANODE AUTOAMTION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211683976.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-09-30
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

Industrial control networks are vulnerable to attacks, and existing detection systems are unable to effectively detect process data tampering, leading to production anomalies, economic losses and security risks.

Method used

An intrusion detection system based on parameter prediction and state verification is adopted. By selecting process parameters with strong correlation, TS fuzzy and matrix decomposition algorithms are used for prediction and verification, and error analysis is combined to locate the intrusion point and determine the cause of data anomaly.

Benefits of technology

It realizes intrusion detection and location of industrial control networks, eliminates the distinction between equipment failures and network attacks, and ensures the safety of production processes and equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116094774B_ABST
    Figure CN116094774B_ABST
Patent Text Reader

Abstract

Industrial control network intrusion detection system and method; a parameter selection module selects process parameters with strong correlation based on the Pearson correlation coefficient and the Spearman rank correlation coefficient; a parameter prediction algorithm module uses an algorithm based on T-S fuzzy and matrix decomposition for prediction; a state verification module is used for verification; the state verification module uses the error β between the predicted value and the detected value of the predicted parameter and the threshold θ of the error β to verify whether there is an abnormality; a network intrusion positioning module uses the error average value e under normal conditions and the threshold σ of β-e in combination with the normal state error curve to locate the intrusion point; the cause of the data abnormality is determined by verification of the preceding and subsequent processes. The present invention predicts key data in the production process through an intelligent algorithm, compares the predicted data with the actual detected data to determine whether the key data is within the normal range, thereby determining whether the system failure is caused by a conventional equipment failure or a network attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial control network security in process industry production and manufacturing, and in particular to an industrial control network intrusion detection system and method based on parameter prediction and state verification. Background Art

[0002] Initially, industrial control networks lacked adequate security considerations. Compared to standard IT networks, industrial control systems are more vulnerable to attack and exploitation. Attackers can steal production data, tamper with process data, and ultimately disrupt the production process, causing economic losses, production safety incidents, or threats to personnel safety. Process data tampered with by attackers through cyberattacks cannot be effectively detected and reported by fault detection systems in traditional control systems until production systems experience anomalies, leading to shutdowns and significant economic losses, or even safety incidents. Summary of the Invention

[0003] The present invention addresses the technical deficiencies identified in the background art. Firstly, it provides an industrial control network intrusion detection system based on parameter prediction and state verification, and secondly, it provides a detection method. Many parameters in industrial control systems are highly correlated and mutually coupled. An intelligent algorithm is used to predict parameters closely related to production safety in process industries. The predicted values ​​are compared with sensor measurements to determine whether the values ​​are within a normal range. A parameter correlation vector representing the production status during normal production is established, along with a causal chain. If a parameter value is abnormal, the causal chain is determined to determine whether the abnormality is caused by equipment failure or a network attack.

[0004] The technical solution adopted by the present invention is: an industrial control network intrusion detection system, specifically including a parameter selection module, a parameter prediction module, a status verification module, a data anomaly cause judgment module, and a network intrusion location module; the industrial control network intrusion detection system implements detection based on parameter prediction and status verification. Using the above detection system to perform industrial control network intrusion detection specifically includes the following steps:

[0005] (1) The parameter selection module selects process parameters with strong correlation for parameter prediction calculation based on the Pearson correlation coefficient and the Spearman rank correlation coefficient;

[0006] (2) The parameter prediction module uses an algorithm based on TS fuzzy and matrix decomposition to predict process parameters;

[0007] (3) The state verification module performs verification, that is, verifies whether there is an abnormality by comparing the predicted value of the predicted process parameter with the error β of the detected value and the threshold θ of the error β;

[0008] (4) The network intrusion positioning module uses the error average value e under normal conditions, the threshold value σ of β-e and the normal state error curve to locate the tampered parameters, and then locate the intrusion point;

[0009] (5) The data anomaly cause judgment module verifies and judges the cause of the data anomaly through the preceding and subsequent processes.

[0010] Compared with the existing technology, the present invention predicts key data in the production process through intelligent algorithms, compares the predicted data with the actual detection data to determine whether the key data is within the normal range. If the detection data is judged to be abnormal data, the abnormal data is located through further prediction in turn, and the production status is used to determine whether the data abnormality is caused by equipment failure or by data tampering due to an attack on the industrial control network. This can determine whether the system failure is caused by a conventional equipment failure or a network attack.

[0011] The prediction algorithm and verification method proposed in this solution can be used to troubleshoot and locate faults in process industry control networks. Furthermore, it can be used to determine whether process data has been tampered with due to network intrusion, and to locate the intrusion. This is of great significance to the production process safety, equipment safety, product quality safety, and personnel safety of process industry control systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 This is a flow chart of the modeling, prediction, and verification calculations of the present invention;

[0013] Figure 2 It is a flowchart of the prediction, verification and positioning process of the present invention;

[0014] Figure 3 It is the prediction, detection and error curve of blast furnace gas generation based on fuzzy rules and matrix decomposition algorithm in the verification process;

[0015] Figure 4 It is the prediction, detection and error curve of gas generation after the hot air pressure data is tampered during the verification process;

[0016] Figure 5 It is the hot air pressure prediction, detection and error curve after the hot air pressure data is tampered during the positioning process;

[0017] Figure 6 It is the prediction, detection and error of other untampered parameters (oxygen enrichment flow) after the hot air pressure data is tampered during the positioning process. DETAILED DESCRIPTION

[0018] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0019] See attached Figures 1-2 The industrial control network intrusion detection method disclosed in the present invention is based on parameter prediction and status verification, and specifically includes a parameter selection module, a parameter prediction algorithm module, a status verification module, a data anomaly cause judgment module and a network intrusion positioning module.

[0020] (1) The parameter selection module of the industrial control network intrusion detection method based on parameter prediction and state verification selects process parameters with strong correlation as inputs of the prediction module based on the Pearson correlation coefficient and the Spearman rank correlation coefficient. The Pearson correlation coefficient calculation formula is as follows:

[0021]

[0022] The calculation formula of Spearman rank coefficient is as follows:

[0023]

[0024] (2) The parameter prediction algorithm module of the industrial control network intrusion detection method based on parameter prediction and state verification adopts an algorithm based on TS fuzzy and matrix decomposition for prediction, and its structure is as follows: Figure 1 shown.

[0025] For n-dimensional input variables x=(x1,x2,…,x n ) T ∈R n and m-dimensional output variable y=(y1,y2,…,y n ) T ∈R m , the i-th fuzzy rule is expressed as formula (1):

[0026]

[0027]

[0028] Where, is the i-th fuzzy rule, r is the number of rules, x1,x2,…,x n are n control parameters used to predict in industrial control systems, are m predicted control parameters;

[0029] Input parameter element x j The membership function of the i-th class is expressed as formula (2):

[0030]

[0031] Where, is the semantic term of the membership function in formula (2), representing the input parameter element x j For the membership degree of the i-th class (i.e. xj Comply with the semantics of the i-th fuzzy rule degree); c ij and σ ij are the mean and variance corresponding to the membership function; relative to the output variables of different dimensions The subsequent parts share a common antecedent (in a multi-input multi-output system, when the input is When Then the kth output function among the r fuzzy rules is expressed as formula (3):

[0032]

[0033] Where, is the corresponding fuzzy rule consequent (i.e., the k-th output of the i-th fuzzy rule = [1, n inputs] multiplied by the weight vector corresponding to each input):

[0034]

[0035] Where, represents the consequent of the i-th fuzzy rule with the k-th output.

[0036] The weight matrix used to predict y (a weight matrix composed of r m-dimensional fuzzy rule consequences, each corresponding to n+1 items, i.e. [1, n inputs]) is as follows:

[0037]

[0038] Substituting formula (4) into formula (3), we have:

[0039]

[0040] Expand the summation relationship and define Φ(x) as shown in formula (6):

[0041] Φ(x)=[φ 1 (x)[1 x T ],φ 2 (x)[1 x T ],…,φ r (x)[1 x T ]] T ∈R r(n+1) (6)

[0042] Then the multi-input multi-output fuzzy model between x and y is expressed as formula (7):

[0043] y=WΦ(x) (7)

[0044] For a given N training data where x eis the e-th n-dimensional input variable, y e is the e-th m-dimensional output variable. The training data is used to build the predictive model and identify W through training.

[0045] According to the principle of least squares method, formula (7) is transformed into the optimal problem of formula (8):

[0046]

[0047] Where, Represents the matrix norm, Y=[y1,y2,…,y N ]∈R m×N ,Ψ=[Φ(x1),Φ(x2),…,Φ(x N )]∈R r(n+1)×N , by solving the optimal problem of formula (8), we can obtain the identification result of the weight matrix W, and then predict y through formula (7);

[0048] The data is divided into r categories by r fuzzy rules, indicating that different process states of the production process correspond to different parameter values; that is, the same few input parameters can produce different output parameters, that is, the output y is an r×1 vector, representing r production process states. Through matrix decomposition, the multi-input multi-output problem can be transformed into a multi-input single-output problem, as shown in formula (9), thereby solving the parameter prediction problem of this scheme;

[0049]

[0050] Where w i is the weight vector of the i-th rule, i.e., the i-th group, and λ,η≥0 are adjustment parameters used to prevent overfitting;

[0051] For group i, apply equation (9) to w i Solving the subdifferential yields:

[0052]

[0053] Where s and t are respectively ||w i The subgradients of ||2 and ‖W‖1, Represents the k-th variable of the i-th group:

[0054]

[0055]

[0056] When the real-time production status of the industrial process does not belong to the i-th category, that is, the i-th group weight value w i = 0, we have:

[0057] ||soft((φ i(x)[1 x T ]) T ε i ,ηλ)||2≤(1-η)λ (13)

[0058] Where, ε i is the partial residual of y, indicating that the parameter groups other than group i should satisfy:

[0059]

[0060] soft(·) is the coordinate soft threshold operator, (soft((z,ηλ)) i =sign(z i )(|z i |-ηλ)) +

[0061] Use formula (13) to determine whether a group of weight values ​​are all zero. If the group of weights is not all zero, that is, w i ≠0, and the input is x i =φ i (x)[1xT]=[A0,A1,…,A n ], the weight vector is Next, we determine whether some elements of the i-th group are zero. We apply Equation (9) to the k-th (k=1,2,…,m) variable of the i-th group. Find the subgradient and we get:

[0062]

[0063] when but:

[0064]

[0065] when but:

[0066]

[0067] Repeat steps (9) to (16) in all groups until convergence, and obtain the weight matrix W. The predicted output y parameter value can be obtained through formula (7), as shown in Figure 2 Prediction curve of blast furnace gas generation.

[0068] (3) The verification steps of the state verification module of the industrial control network intrusion detection method based on parameter prediction and state verification are as follows:

[0069] S1. Select the key parameter y to be predicted, and calculate a set of process parameters x1, x2, ..., x3 with strong correlation for predicting the key parameter by Pearson correlation coefficient and Spearman rank correlation coefficient. n ;

[0070] S2, calculate the deviation β between the predicted and detected values ​​of all parameters in S1, the threshold θ of β, the average value e of β under normal conditions, and the threshold σ of β-e based on the historical parameter data;

[0071] S3, using real-time detection of input parameters x1, x2, ..., x n The output parameter y predicted by the prediction model established by formula (7) is compared with the output parameter detected by the sensor. If β>θ, it is determined that the industrial control system is in an abnormal state at this moment;

[0072] S4, further locate the anomaly, in order at x1, x2, ..., x n Select n-1 parameters to predict the nth parameter: if the deviation between the predicted result of the parameter and its detected value β>θ and β-e≥σ, then the parameter other than the parameter is judged to be abnormal; if β>θ and β-e<σ, then the parameter is judged to be abnormal;

[0073] S5. Repeat the predictions from S1 to S4 in turn until the abnormal parameters are found.

[0074] (4) For abnormal parameters, the elimination method and the previous process prediction method are used to determine whether the cause of the current abnormality is a failure of the control system hardware equipment or the sensor data has been invaded and tampered by a network attacker. The judgment rules are as follows:

[0075] R1. If the predicted value is inaccurate, the detected value is accurate, and the subsequent process parameter value matches the detected value, then the parameter sensor used for prediction is faulty;

[0076] R2, if the predicted value is accurate, the detected value is inaccurate, and the subsequent process parameter value matches the predicted value, then the sensor corresponding to the predicted parameter is faulty;

[0077] R3. If the predicted value is inaccurate, the test value is accurate, and the subsequent process parameter value matches the test value, the parameters used for prediction have been tampered with;

[0078] R4. If the predicted value is accurate, the detected value is inaccurate, and the subsequent process parameter value matches the predicted value, the data corresponding to the predicted parameter has been tampered with;

[0079] If the cause of the current abnormality is determined to be a sensor failure based on R1 or R2, further determination is made as to whether it is a data loss failure or a data drift failure, as follows:

[0080] R11, if the parameter is in the state of no data, the sensor has a data missing fault;

[0081] R12. If the data changes gradually rather than abruptly over a long period of time, the sensor has a data drift fault.

[0082] The present invention is described below with reference to preferred embodiments.

[0083] In the ironmaking blast furnace control system, a programmable logic controller is used to collect sensor data and control the actuators to adjust the process operation status after program calculation. The controller is connected to the human-computer interaction computer and information management computer through an industrial network.

[0084] Using the parameter selection module, the process parameters with strong correlation are selected from the process parameters according to the Pearson correlation coefficient and the Spearman rank correlation coefficient: hot air pressure, cold air temperature, cold air flow, standard wind speed, blast kinetic energy, furnace gas volume, oxygen enrichment flow, oxygen enrichment pressure and cold air pressure.

[0085] The parameter prediction module is used to predict the gas production of the blast furnace based on the parameter prediction algorithm using the above 9 process parameters. At the same time, the 9 parameters are mutually predicted. The root mean square error and standard deviation of the predicted value and the measured value are shown in the "normal" column of Table 1. After the hot air pressure parameter was tampered with due to a network attack (170 sets of data during the period), the root mean square error and standard deviation of the predicted value and the measured value calculated according to the above process are shown in the "after attack" column of Table 1. The predicted value, measured value and error value in various cases are shown in Figures 3 to 6 .

[0086] Table 1 Root mean square error (RMSE) and standard deviation (STD) of normal and tampered parameter prediction values

[0087]

[0088] Using the state verification module and the network intrusion location module, we can calculate through the state verification method and obtain:

[0089] (a) After the hot air pressure sensor data is tampered, the root mean square errors of the predicted values ​​of 10 parameters, including the gas generation amount, are much higher than those in the untampered state. The deviation β between the predicted value and the measured value increases significantly after tampering, that is, β>θ;

[0090] (b) After the hot air pressure sensor data is tampered with, the predicted value of the hot air pressure is relatively accurate. The error curves before and after tampering are consistent, and the standard deviation of the predicted value error is extremely close, that is, β-e < σ; for other parameters except hot air pressure, β-e ≥ σ.

[0091] Therefore, we can conclude that the system is in an abnormal state and the hot air pressure parameter has been tampered with, while other parameters have not been tampered with. It can be seen that the calculation and judgment results are completely consistent with the actual situation.

Claims

1. A method for detecting intrusion in an industrial control network, characterized by: An industrial control network intrusion detection system is applied to detect intrusions in the industrial control network. The detection system specifically includes a parameter selection module, a parameter prediction module, a state verification module, a data anomaly cause judgment module, and a network intrusion location module. The industrial control network intrusion detection system implements detection based on parameter prediction and state verification. The detection method specifically includes the following steps: (1) The parameter selection module selects process parameters with strong correlation based on the Pearson correlation coefficient and the Spearman rank correlation coefficient for parameter prediction calculation; (2) The parameter prediction module uses an algorithm based on TS fuzzy and matrix decomposition to predict process parameters; (3) The state verification module performs verification by comparing the error between the predicted value and the detected value of the predicted process parameter. β ,error β Threshold θ Verify whether there is an abnormality; (4) The network intrusion positioning module uses the average error value under normal conditions e、β-e The threshold σ is combined with the normal state error curve to locate the tampered parameters and then locate the intrusion point; (5) The data anomaly cause judgment module verifies and judges the cause of the data anomaly through the preceding and subsequent processes.

2. The industrial control network intrusion detection method according to claim 1, characterized in that: The method for status verification and abnormal parameter location in steps (3) and (4) is as follows: S1. Select the key parameters to be predicted y , a set of process parameters with strong correlation for predicting key parameters were selected by calculating the Pearson correlation coefficient and the Spearman rank correlation coefficient ; S2. Calculate the deviation between the predicted value and the detected value of all parameters in S1 based on the historical parameter data. β , β Threshold θ , under normal conditions β Average value e , β−e Threshold σ ; S3. Using real-time detection input parameters Output parameters predicted by the prediction model y Compared with the output parameters detected by the sensor, if β > θ , then it is determined that the industrial control system is in an abnormal state at this moment; S4, further locate the abnormality, in turn Select n−1 Parameter pair n Parameters are predicted: If the deviation between the predicted result of the parameter and its detected value β > θ and β − e ≥ σ , then it is determined that the parameters other than this parameter are abnormal; like β > θ and β − e < σ , then the parameter is judged to be abnormal; S5. Repeat the predictions from S1 to S4 in turn until the abnormal parameters are found.

3. The industrial control network intrusion detection method according to claim 1, characterized in that: In step (5), the method for determining the cause of data anomaly is as follows: For abnormal parameters, we use a combination of elimination and previous process prediction to determine whether the cause of the current abnormality is a control system hardware failure or sensor data tampering by a network attacker. The judgment rules are as follows: R1. If the predicted value is inaccurate, the detected value is accurate, and the subsequent process parameter value matches the detected value, then the parameter sensor used for prediction is faulty; R2, if the predicted value is accurate, the detected value is inaccurate, and the subsequent process parameter value matches the predicted value, then the sensor corresponding to the predicted parameter is faulty; R3. If the predicted value is inaccurate, the test value is accurate, and the subsequent process parameter value matches the test value, the parameters used for prediction have been tampered with; R4. If the predicted value is accurate, the detected value is inaccurate, and the subsequent process parameter value matches the predicted value, the data corresponding to the predicted parameter has been tampered with; If the cause of the current abnormality is determined to be a sensor failure based on R1 or R2, further determination is made as to whether it is a data loss failure or a data drift failure, as follows: R11, if the parameter is in the state of no data, the sensor has a data missing fault; R12. If the data changes gradually rather than abruptly over a long period of time, the sensor has a data drift fault.

Citation Information

Patent Citations

  • Wind turbine generator state parameter abnormity identification method based on combination prediction

    CN105719002A

  • Blast furnace bosh gas volume prediction method and program for multi-clustering prototype-based T-S model

    CN108460213A