An industrial control intrusion detection and auditing method and a computer-readable storage medium

By assigning separate audit and intrusion detection processes to each session in industrial control systems, the method enhances reliability by preventing crashes from disrupting operations.

CN116132130BActive Publication Date: 2025-07-15BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211714002.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-29
Publication Date
2025-07-15
Estimated Expiration
2042-12-29

AI Technical Summary

Technical Problem

Due to the same process, the industrial control intrusion detection and audit equipment uses the same process, which causes the process to crash when it is not handled, resulting in poor reliability of the industrial control system.

Method used

Through the integrated scheduling unit, the intrusion detection and security audit processes are managed, ensuring that each session information corresponds to an independent audit process and intrusion detection process, the collection and distribution of message information is realized, and when the process crashes, switch to another process to continue processing unfinished messages.

Benefits of technology

It improves the reliability of industrial control intrusion detection and auditing, avoids the impact of single process crashes on other businesses, and ensures the stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132130B_ABST
    Figure CN116132130B_ABST
Patent Text Reader

Abstract

The present application provides an industrial control intrusion detection and auditing method and a computer-readable storage medium. The method includes obtaining session information to which a detection message belongs; determining a target auditing process and a target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs; sending the detection message and the session information to which it belongs to the target auditing process; obtaining a first message returned by the target auditing process; wherein the first message includes the detection message, the session information to which it belongs, and industrial control protocol elements, and the industrial control protocol elements are obtained by the target auditing process through industrial control protocol identification and parsing according to the detection message and the session information to which it belongs; sending the first message to the target intrusion detection process, so that the target intrusion detection process performs attack intrusion detection according to the detection message, the industrial control protocol elements, and a preset attack detection rule library, thereby greatly improving the reliability of industrial control intrusion detection and auditing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology. Specifically, it relates to an industrial control intrusion detection and auditing method and a computer-readable storage medium. Background Art

[0002] In an industrial control environment, an industrial control intrusion detection and auditing device collects industrial control traffic from a switch mirror port, performs industrial control protocol auditing and industrial control protocol intrusion detection. As a security device in the industrial control environment, its role is becoming increasingly important.

[0003] The two core functions of an industrial control intrusion detection and auditing device, namely protocol auditing for industrial control protocols and intrusion detection for industrial control protocols, both involve the protocol parsing and restoration of industrial control protocols. Therefore, to improve processing performance, generally, the two functional points of intrusion detection and security auditing are placed in the same thread or the same process to achieve the purpose of "parsing the protocol once and using the functions twice".

[0004] However, when using the same thread or process for intrusion detection and security auditing, if the process crashes due to improper handling, it will cause all services of intrusion detection and security auditing to be interrupted, resulting in poor reliability of the industrial control system. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide an industrial control intrusion detection and auditing method and a computer-readable storage medium to solve the problem of poor reliability caused by using the same process for current industrial control intrusion detection and auditing devices.

[0006] In a first aspect, the present invention provides an industrial control intrusion detection and auditing method. This method is applied to a comprehensive scheduling unit and includes: obtaining session information to which a detection message belongs; determining a target auditing process and a target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs; where each session information corresponds to an auditing process and an intrusion detection process, and the auditing processes and intrusion detection processes corresponding to different session information are different; sending the detection message and the session information to which it belongs to the target auditing process; obtaining a first message returned by the target auditing process; where the first message includes the detection message, the session information to which it belongs, and industrial control protocol elements, and the industrial control protocol elements are obtained by the target auditing process through industrial control protocol identification and parsing according to the detection message and the session information to which it belongs; sending the first message to the target intrusion detection process so that the target intrusion detection process performs attack intrusion detection according to the detection message, the industrial control protocol elements, and a preset attack detection rule library.

[0007] For the industrial control intrusion detection and auditing method with the above design, in this solution, the message information is collected and distributed through the comprehensive scheduling unit, and the processes of the two services of intrusion detection and security auditing are managed. Moreover, the intrusion detection and security auditing processes managed by the comprehensive scheduling unit designed in this solution are independent of each other, so that even if one service process crashes, it will not affect the other service. At the same time, each session information corresponds to one process, so that even if the process of one session information crashes, it will not affect the security auditing and intrusion detection of other session information, thus greatly improving the reliability of industrial control intrusion detection and auditing.

[0008] In an alternative implementation manner of the first aspect, determining the target auditing process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs includes: determining whether the session information to which the detection message belongs is the created session information; if it is determined that the session information to which the detection message belongs is the created session information, obtaining the first process identifier and the second process identifier in the session information to which the detection message belongs; searching for the target auditing process in multiple auditing processes according to the first process identifier, and searching for the target intrusion detection process in multiple intrusion detection processes according to the second process identifier.

[0009] In an alternative implementation manner of the first aspect, wherein the session information includes the source IP address and the destination IP address to which the detection message belongs; after determining whether the session information to which the detection message belongs is the created session information, the method further includes: if it is determined that the session information to which the detection message belongs is not created, obtaining the first total number of the current auditing processes and the second total number of the current intrusion detection processes; calculating the target auditing process to which the detection message belongs according to the first total number, the source IP address to which the detection message belongs, and the destination IP address; calculating the target intrusion detection process to which the detection message belongs according to the second total number, the source IP address to which the detection message belongs, and the destination IP address.

[0010] In an alternative implementation manner of the first aspect, determining whether the session information to which the detection message belongs is the created session information includes: searching in multiple created session information to find whether there is session information that is the same as the source IP address, the destination IP address, the source port, the destination port, and the transport layer protocol of the detection message; if session information that is the same as the source IP address, the destination IP address, the source port, the destination port, and the transport layer protocol of the detection message is found in multiple created session information, determining that the session information to which the detection message belongs is created; if session information that is the same as the source IP address, the destination IP address, the source port, the destination port, and the transport layer protocol of the detection message is not found in multiple created session information, determining that the session information to which the detection message belongs is not created.

[0011] In an alternative implementation of the first aspect, after sending the first message to the target intrusion detection process, the method further includes: obtaining a private data release method in the session information to which the detection message belongs; when the session corresponding to the session information to which the detection message belongs ends, clearing the audit data of the target audit process and the detection data of the target intrusion detection process in the memory according to the private data release method in the session information to which the detection message belongs.

[0012] In an alternative implementation of the first aspect, the method further includes: obtaining the heartbeat information of each audit process and intrusion detection process; determining whether there is a process crash according to the heartbeat information of each audit process and intrusion detection process; if it is determined that there is a process crash, obtaining the message that has been processed by the crashed process and determining the type of the crashed process; if it is determined that the crashed process is an audit process, sending the message that has been processed to the target intrusion detection process corresponding to the message that has been processed for intrusion detection, updating the identifier of the audit process in the session information to which the detection message belongs to be empty, and clearing the audit data corresponding to the crashed process.

[0013] In an alternative implementation of the first aspect, after determining the type of the crashed process, the method further includes: if it is determined that the crashed process is an intrusion detection process, updating the identifier of the intrusion detection process in the session information to which the detection message belongs to be empty, and releasing the detection message.

[0014] In an alternative implementation of the first aspect, after determining that there is a process crash, the method further includes: obtaining the unprocessed detection messages of the crashed process and determining the type of the crashed process; if it is determined that the crashed process is an audit process, obtaining the third total number of the audit process, where the third total number is the first total number of the current audit process minus 1; calculating the updated target audit process to which the unprocessed detection message belongs according to the third total number, the source IP address and the destination IP address to which the unprocessed detection message belongs; sending the unprocessed detection message to the updated target audit process.

[0015] In an alternative implementation of the first aspect, after obtaining the unprocessed detection messages of the crashed process and determining the type of the crashed process, the method further includes: if it is determined that the crashed process is an intrusion detection process, obtaining the fourth total number of the intrusion detection process, where the fourth total number is the second total number of the current intrusion detection process minus 1; calculating the updated target intrusion detection process to which the unprocessed detection message belongs according to the fourth total number, the source IP address and the destination IP address to which the unprocessed detection message belongs; sending the unprocessed detection message to the updated target intrusion detection process.

[0016] In the implementation manner of the above design, in the case where the audit detection process or the intrusion detection process crashes, by selecting another audit process or intrusion detection process to continue processing the unprocessed detection messages, the reliability of industrial control audit and intrusion detection is further improved.

[0017] In a second aspect, the present application provides an industrial control intrusion detection and audit device, which includes an acquisition module, a determination module, and a sending module; the acquisition module is used to acquire the session information to which the detection message belongs; the determination module is used to determine the target audit process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs; wherein, each session information corresponds to an audit process and an intrusion detection process, and the audit processes and intrusion detection processes corresponding to different session information are different; the sending module is used to send the detection message and the session information to which it belongs to the target audit process; the acquisition module is further used to acquire the first message information returned by the target audit process; wherein, the first message information includes the detection message, the session information to which it belongs, and industrial control protocol elements, and the industrial control protocol elements are obtained by the target audit process through industrial control protocol identification and parsing according to the detection message and the session information to which it belongs; the sending module is further used to send the first message information to the target intrusion detection process, so that the target intrusion detection process performs attack intrusion detection according to the detection message, the industrial control protocol elements, and the preset attack detection rule library.

[0018] For the industrial control intrusion detection and audit device of the above design, in this solution, the integrated scheduling unit is used to collect and distribute message information, and manage the processes of intrusion detection and security audit. Moreover, the intrusion detection and security audit processes managed by the integrated scheduling unit designed in this solution are independent of each other, so that even if one service process crashes, it will not affect the other service; at the same time, each session information corresponds to a process, so that even if the process of one session information crashes, it will not affect the security audit and intrusion detection of other session information, thereby greatly improving the reliability of industrial control intrusion detection and audit.

[0019] In an optional implementation manner of the second aspect, the determination module is specifically used to determine whether the session information to which the detection message belongs is the created session information; if it is determined that the session information to which the detection message belongs is the created session information, then acquire the first process identifier and the second process identifier in the session information to which the detection message belongs; search for the target audit process in multiple audit processes according to the first process identifier, and search for the target intrusion detection process in multiple intrusion detection processes according to the second process identifier.

[0020] In an alternative embodiment of the second aspect, the session information includes the source IP address and the destination IP address to which the detection message belongs; the determining module is further specifically configured to, if it is determined that the session information to which the detection message belongs has not been created, obtain the first total number of the current audit processes and the second total number of the current intrusion detection processes; calculate the target audit process to which the detection message belongs according to the first total number, the source IP address and the destination IP address to which the detection message belongs; and calculate the target intrusion detection process to which the detection message belongs according to the second total number, the source IP address and the destination IP address to which the detection message belongs.

[0021] In an alternative embodiment of the second aspect, the determining module is further specifically configured to search for session information in the multiple created session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message; if session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is found in the multiple created session information, it is determined that the session information to which the detection message belongs has been created; if session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is not found in the multiple created session information, it is determined that the session information to which the detection message belongs has not been created.

[0022] In an alternative embodiment of the second aspect, the obtaining module is further configured to obtain the private data release method in the session information to which the detection message belongs; the apparatus further includes a clearing module, configured to, when the session corresponding to the session information to which the detection message belongs ends, clear the audit data of the target audit process and the detection data of the target intrusion detection process in the memory according to the private data release method in the session information to which the detection message belongs.

[0023] In an alternative embodiment of the second aspect, the obtaining module is further configured to obtain the heartbeat information of each audit process and intrusion detection process; the judging module is configured to judge whether there is a process crash according to the heartbeat information of each audit process and intrusion detection process; the obtaining module is further configured to, after the judging module judges that there is a process crash, obtain the message of the processed packets of the crashed process; the judging module is further configured to judge the type of the crashed process; the sending module is further configured to, after the judging module determines that the crashed process is an audit process, send the message of the processed packets to the corresponding target intrusion detection process for intrusion detection, update the identifier of the audit process in the session information to which the detection message belongs to be empty, and empty the audit data corresponding to the crashed process.

[0024] In an alternative embodiment of the second aspect, the apparatus further includes an update and release module, configured to, after the determination module determines that the crashed process is an intrusion detection process, update the identifier of the intrusion detection process in the session information to which the detection message belongs to be empty, and release the detection message.

[0025] In a third aspect, the present application provides an electronic device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, it executes the method in the first aspect or any optional implementation manner in the first aspect.

[0026] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it executes the method in the first aspect or any optional implementation manner in the first aspect.

[0027] In a fifth aspect, the present application provides a computer program product, which, when running on a computer, causes the computer to execute the method in the first aspect or any optional implementation manner in the first aspect.

[0028] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically given below. Description of the Drawings

[0029] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0030] Figure 1 It is a schematic flowchart of the industrial control intrusion detection and auditing method provided by the embodiment of the present application;

[0031] Figure 2 It is a schematic structural diagram of the industrial control intrusion detection and auditing apparatus provided by the embodiment of the present application;

[0032] Figure 3 It is a schematic structural diagram of the electronic device provided by the embodiment of the present application.

[0033] Icons: 200 - Acquisition module; 210 - Determination module; 220 - Sending module; 230 - Clearing module; 240 - Judgment module; 250 - Update and release module; 3 - Electronic device; 301 - Processor; 302 - Memory; 303 - Communication bus. Detailed implementation manners

[0034] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0035] In the industrial control environment, the industrial control intrusion detection and auditing device collects industrial control traffic from the switch mirror port, performs industrial control protocol auditing and industrial control protocol intrusion detection. As a security device in the industrial control environment, its role is becoming more and more important.

[0036] Two core functions of the industrial control intrusion detection and auditing device, protocol auditing for industrial control protocols and intrusion detection for industrial control protocols, both of these functions involve protocol parsing and restoration of industrial control protocols. Therefore, to improve processing performance, generally, the two function points of intrusion detection and security auditing are placed in the same thread or the same process to achieve the purpose of "one protocol parsing, two function usages".

[0037] The inventors of the present application found that when the two function points of intrusion detection and security auditing are implemented in the same thread or the same process, due to the complexity and variability of application protocols, improper processing may lead to process crashes, and process crashes will cause all services of intrusion detection and security auditing to be interrupted, resulting in poor reliability of the intrusion detection and auditing system.

[0038] Based on the above problems, the inventors of the present application designed an industrial control intrusion detection and auditing method and a computer-readable storage medium. The comprehensive scheduling unit is used to collect and distribute message information, and manage the processes of intrusion detection and security auditing. Moreover, the intrusion detection and security auditing processes managed by the comprehensive scheduling unit designed in this solution are independent of each other, so that even if one service process crashes, it will not affect the other service; at the same time, each session information corresponds to a process, so that even if the process of one session information crashes, it will not affect the security auditing and intrusion detection of other session information, thus greatly improving the reliability of industrial control intrusion detection and auditing.

[0039] Based on the above ideas, the present application provides an industrial control intrusion detection and auditing method, which can be applied to a comprehensive scheduling unit. The comprehensive scheduling unit includes but is not limited to a computer, a server, a host computer, etc. Figure 1 As shown, this method can be implemented in the following manner:

[0040] Step S100: Obtain the session information to which the detection message belongs.

[0041] Step S110: Determine the target audit process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs.

[0042] Step S120: Send the detection message and the associated session information to the target audit process.

[0043] Step S130: Obtain the first message from the target audit process.

[0044] Step S140: Send the first message to the target intrusion detection process.

[0045] In this embodiment, the computing device divides a shared memory area for the integrated management unit, the audit process, and the intrusion detection process to use. The size of the shared memory can depend on the size of the system physical memory. The larger the system physical memory, the larger the shared memory area can be created.

[0046] After the audit process and the intrusion detection process are started, they can map to their respective process spaces in the shared memory area, so as to detect data through the corresponding process idle storage, etc.

[0047] The integrated scheduling unit can manage multiple processes. For example, it can manage multiple audit processes and multiple intrusion detection processes. Each process has a unique identifier of the corresponding process, the occupied memory space, the method for releasing the memory space data, the message sending queue of the corresponding process, and the message recovery queue of the corresponding process, etc.

[0048] Specifically, the audit process and the intrusion detection process can send registration information to the integrated scheduling unit. The registration information can include the process unique identifier, the process type identifier (audit / intrusion detection), the method for releasing the memory space data, etc. Then, the integrated scheduling unit can allocate a message sending queue, a message recovery queue, and the occupied memory space to the registered process.

[0049] On the above basis, the integrated scheduling unit can obtain the session information to which the detection message belongs. Among them, the integrated scheduling unit can capture the original message from the physical network card to obtain the detection message, and then find the session information to which it belongs according to the detection message. Among them, the same session information can include multiple different messages, and the messages belonging to the same session information have the same five-tuple, and the five-tuple includes the source IP address, the destination IP address, the source port, the destination port, and the transport layer protocol.

[0050] This solution can determine whether the session information to which the detection message belongs is the created session information. Specifically, this solution can search in multiple created session information to find out whether there is session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message. If there is no session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message, it means that the session information to which the detection message belongs has not been created. If session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is found, it means that the session information to which the detection message belongs has been created. Among them, each session information corresponds to an audit process and an intrusion detection process, and different session information corresponds to different audit processes and intrusion detection processes.

[0051] As a possible implementation manner, based on the fact that the session information to which the detection message belongs has been created, this solution can obtain the first process identifier and the second process identifier in the session information to which the detection message belongs. Among them, the first process identifier can be the audit process identifier corresponding to the session information, and the second process identifier can be the intrusion detection process identifier corresponding to the session information. Thus, the target audit process is searched in multiple audit processes according to the first process identifier, and the target intrusion detection process is searched in multiple intrusion detection processes according to the second process identifier, so as to determine the target audit process and the target intrusion detection process to which the detection message belongs.

[0052] As another possible implementation manner, based on the fact that the session information to which the detection message belongs has not been created, this solution can create the session information corresponding to the detection message. The first process identifier and the second process identifier of this session information can be initialized to null values. On this basis, this solution can obtain the first total number of the current audit processes and the second total number of the current intrusion detection processes, and then calculate the target audit process to which the detection message belongs according to the first total number, the source IP address to which the detection message belongs, and the destination IP address.

[0053] For example, the first total number of the current audit processes is AN. On this basis, this solution can use the number AN, the source IP address to which the detection message belongs, and the destination IP address to calculate the target audit process identifier of the detection message, so as to update the first process identifier (null value) of the session information to which the detection message belongs according to the calculated target audit process identifier.

[0054] Specifically, this solution can calculate the hash value according to the source IP address and the destination IP address to which the detection message belongs, and then take the modulus with respect to the number AN based on the hash value, so as to calculate the obtained target audit process identifier.

[0055] Similarly, to calculate the target intrusion detection process to which the detection message belongs, it can be calculated based on the second total number, the source IP address, and the destination IP address to which the detection message belongs. Specifically, this solution can calculate the hash value based on the source IP address and the destination IP address to which the detection message belongs, and then take the modulo of the second total number IN of the intrusion detection process based on the hash value, so as to calculate the target intrusion detection process identifier and update the second process identifier (null value) of the session information to which the detection message belongs.

[0056] Through the above method, this solution can determine the target audit process and the target intrusion detection process corresponding to the session information to which the detection message belongs. On this basis, this solution can first send the detection message and the affiliated session information to the target audit process. The target audit process can identify and parse the industrial control protocol according to the detection message and the session information to which the detection message belongs, restore the industrial control protocol elements, and then package the industrial control protocol elements, the detection message, and the session information to which the detection message belongs into the first message and return it to the integrated scheduling unit.

[0057] Specifically, as described above, each audit process and intrusion detection process is allocated a corresponding message sending queue and message receiving queue. On this basis, the integrated scheduling unit can send the detection message and the affiliated session information to the target audit process through the message sending queue corresponding to the target audit process; the target audit process can also return the first message to the integrated scheduling unit through the corresponding message receiving queue.

[0058] In addition, it should be noted here that after the target audit process restores the industrial control protocol elements, the target audit process can also generate industrial control audit events according to the industrial control protocol elements, and generate an alarm when there is an audit problem in the public audit event. In addition, the target audit process can also cache the restored public

[0059] protocol elements in the cache area allocated to the target audit process, so as to realize the retention of data.

[0060] Based on the foregoing description, after the integrated scheduling unit receives the first message returned by the target audit process through the message receiving queue, the integrated scheduling unit can send the first message to the target intrusion detection process through the message sending queue corresponding to the target intrusion detection process.

[0061] The target intrusion detection process reads the first message through the message sending queue, obtains the detection message in the first message, the session information to which the detection message belongs, and the industrial control protocol elements in the first message, and then performs attack detection according to the detection message, the industrial control protocol elements, and the built-in attack detection rule library, so as to obtain the intrusion detection result. If an attack behavior is found in the intrusion detection result, the target intrusion detection process can issue an alarm.

[0062] In addition, the target intrusion detection process can cache information such as the generated intrusion detection results into the corresponding cache area allocated for 5, so as to achieve data retention.

[0063] For the industrial control intrusion detection and auditing method designed above, in this solution, the comprehensive scheduling unit is used to collect and distribute message information, and manage the processes of intrusion detection and security auditing. Moreover, the intrusion detection and security auditing processes managed by the comprehensive scheduling unit designed in this solution are independent of each other, so that

[0064] even if one business process crashes, it will not affect the other business; at the same time, each session information corresponds to a process, so that even if the process of one session information crashes, it will not affect the security auditing and intrusion detection of other session information, thus greatly improving the reliability of industrial control intrusion detection and auditing.

[0065] In an alternative implementation manner of this embodiment, as described above, each session information corresponds to an allocated cache area. On this basis, each session information in this solution includes a corresponding private data release method, which is used to release the audit data and intrusion detection data of the corresponding session information. This solution can obtain the private data release method in the session information to which the detection message belongs. When the session corresponding to the session information to which the detection message belongs ends, this solution can clear the audit data of the target audit process and the detection data of the target intrusion detection process in the memory according to the private data release method in the session information to which the detection message belongs, so as to release the cache and provide memory space for subsequent sessions.

[0066] In an alternative implementation manner of this embodiment, this solution can obtain the heartbeat information of each process. For example, it can obtain the heartbeat information of each audit process and each intrusion detection process. According to the heartbeat information of each process, it can judge whether there is a process crash among multiple processes. If it is determined that there is a process crash, it will obtain the processed message information of the crashed process and the unprocessed message information of the crashed process, and judge the type of the crashed process.

[0067] If the crashed process is an audit process, it will send the processed message information to the target intrusion detection process corresponding to the processed message information for intrusion detection, update the identifier of the audit process in the session information to which the detection message belongs to be empty, and clear the audit data corresponding to the crashed process.

[0068] Moreover, when the crashed process is the audit process, and there are still unprocessed message packets, the present solution can obtain the third total number of the audit process, where the third total number is the first total number of the current audit process minus 1. For example, if the first total number is the aforementioned AN, then the third total number is AN - 1. Then, based on the third total number AN - 1, the source IP address and the destination IP address to which the unprocessed detection packet belongs, the updated target audit process to which the unprocessed detection packet belongs is calculated, and then the unprocessed detection packet is sent to the updated target audit process for audit processing, so that the unprocessed detection packet can be audited through the updated target audit process. Among them, the method for calculating the updated target audit process to which the unprocessed detection packet belongs is the same as the method for calculating the target audit process described above, and will not be elaborated here.

[0069] If the crashed process is the intrusion detection process, for the processed detection packets, since the industrial control intrusion detection has been completed, there is no need to process them anymore. Therefore, the present solution only needs to update the identifier of the intrusion detection process in the session information to which the detection packet belongs to be empty and release the detection packet.

[0070] Based on the crashed process being the intrusion detection process, for the unprocessed detection packets, it means that the industrial control audit has been completed but the intrusion detection has not been completed. Therefore, the present solution obtains the fourth total number of the intrusion detection process, where the fourth total number is the second total number of the current intrusion detection process minus 1. For example, if the second total number described above is IN, then the fourth total number is IN - 1. On this basis, the present solution calculates the updated target intrusion detection process to which the unprocessed detection packet belongs based on the fourth total number, the source IP address and the destination IP address to which the unprocessed detection packet belongs, and then sends the unprocessed detection packet to the updated target intrusion detection process for intrusion detection of the unprocessed detection packet.

[0071] In the implementation manner of the above design, when the audit detection process or the intrusion detection process crashes, the present solution further improves the reliability of industrial control audit and intrusion detection by selecting another audit process or intrusion detection process to continue processing the unprocessed detection packets.

[0072] Figure 2 shows a schematic structural block diagram of an industrial control intrusion detection and audit device provided by the present application. It should be understood that this device is related to Figure 1The method embodiment executed in the embodiment corresponds to the method embodiment executed in the embodiment, and the steps involved in the aforementioned method can be executed. The specific functions of the device can be referred to the description above. To avoid repetition, the detailed description is appropriately omitted here. The device includes at least one software function module that can be stored in a memory in the form of software or firmware or fixed in the operating system (OS) of the device.

[0073] Specifically, the device includes: an acquisition module 200, a determination module 210 and a sending module 220; the acquisition module 200 is used to acquire the session information to which the detection message belongs; the determination module 210 is used to determine the target audit process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs; wherein each session information corresponds to an audit process and an intrusion detection process, and different session information corresponds to different audit processes and intrusion detection processes; the sending module 220 is used to send the detection message and the session information to which it belongs to the target audit process; the acquisition module 200 is also used to acquire the first message returned by the target audit process; wherein the first message includes the detection message, the session information to which it belongs and the industrial control protocol elements, and the industrial control protocol elements are obtained by the target audit process through industrial control protocol identification and parsing according to the detection message and the session information to which it belongs; the sending module 220 is also used to send the first message to the target intrusion detection process, so that the target intrusion detection process performs attack intrusion detection according to the detection message, the industrial control protocol elements and the preset attack detection rule library.

[0074] The industrial control intrusion detection and auditing device designed above realizes the collection and distribution of message information through the comprehensive scheduling unit, and manages the processes of the two businesses of intrusion detection and security auditing. The intrusion detection and security auditing processes managed by the comprehensive scheduling unit designed in this scheme are independent of each other, so that even if one business process crashes, it will not affect the progress of another business; at the same time, each session information corresponds to a process, so that even if the process of one session information crashes, it will not affect the security audit and intrusion detection of other session information, thereby greatly improving the reliability of industrial control intrusion detection and auditing.

[0075] In an optional implementation manner of the present embodiment, the determination module 210 is specifically used to determine whether the session information to which the detection message belongs is the created session information; if it is determined that the session information to which the detection message belongs is the created session information, then obtain the first process identifier and the second process identifier in the session information to which the detection message belongs; search for the target audit process in multiple audit processes according to the first process identifier, and search for the target intrusion detection process in multiple intrusion detection processes according to the second process identifier.

[0076] In an alternative embodiment of the present embodiment, the session information includes the source IP address and the destination IP address to which the detection message belongs; the determining module 210 is further specifically configured to, if it is determined that the session information to which the detection message belongs has not been created, obtain the first total number of the current audit processes and the second total number of the current intrusion detection processes; calculate the target audit process to which the detection message belongs according to the first total number, the source IP address and the destination IP address to which the detection message belongs; and calculate the target intrusion detection process to which the detection message belongs according to the second total number, the source IP address and the destination IP address to which the detection message belongs.

[0077] In an alternative embodiment of the present embodiment, the determining module 210 is further specifically configured to search in multiple created session information to find out whether there is session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message; if session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is found in the multiple created session information, it is determined that the session information to which the detection message belongs has been created; if session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is not found in the multiple created session information, it is determined that the session information to which the detection message belongs has not been created.

[0078] In an alternative embodiment of the present embodiment, the obtaining module 200 is further configured to obtain the private data release method in the session information to which the detection message belongs; the apparatus further includes a clearing module 230, configured to, when the session corresponding to the session information to which the detection message belongs ends, clear the audit data of the target audit process and the detection data of the target intrusion detection process in the memory according to the private data release method in the session information to which the detection message belongs.

[0079] In an alternative embodiment of the present embodiment, the obtaining module 200 is further configured to obtain the heartbeat information of each audit process and intrusion detection process; the judging module 240 is configured to judge whether there is a process crash according to the heartbeat information of each audit process and intrusion detection process; the obtaining module 200 is further configured to, after the judging module 240 judges that there is a process crash, obtain the message of the packets that have been processed by the crashed process; the judging module 240 is further configured to judge the type of the crashed process; the sending module 220 is further configured to, after the judging module 240 determines that the crashed process is an audit process, send the message of the packets that have been processed to the target intrusion detection process corresponding to the message of the packets that have been processed for intrusion detection, update the identifier of the audit process in the session information to which the detection message belongs to be empty, and empty the audit data corresponding to the crashed process.

[0080] In an alternative implementation of this embodiment, the device further includes an update and release module 250, configured to, after the determination module determines that the crashed process is the intrusion detection process, update the identifier of the intrusion detection process in the session information to which the detection message belongs to be empty, and release the detection message.

[0081] According to some embodiments of the present application, as Figure 3 shown, the present application provides an electronic device 3, including: a processor 301 and a memory 302. The processor 301 and the memory 302 are interconnected and communicate with each other through a communication bus 303 and / or other forms of connection mechanisms (not shown). The memory 302 stores a computer program executable by the processor 801. When the computing device runs, the processor 301 executes the computer program to execute the methods performed in the foregoing implementation manners, such as steps S100 to S120: obtaining the session information to which the detection message belongs; determining the target audit process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs; sending the detection message and the belonging session information to the target audit process; obtaining the first message information returned by the target audit process; and sending the first message information to the target intrusion detection process.

[0082] The present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the methods performed previously.

[0083] Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-OnlyMemory, abbreviated as ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0084] The present application provides a computer program product, which, when running on a computer, causes the computer to execute the foregoing methods.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application, and they should all be covered by the scope of the claims and the specification of the present application. In particular, as long as there is no structural conflict, the technical features mentioned in each embodiment can be combined in any way. The present application is not limited to the specific embodiments disclosed in the text, but includes all technical solutions that fall within the scope of the claims.

Claims

1. An industrial control intrusion detection and auditing method, characterized in that The method is applied to an integrated scheduling unit, and the method includes: Obtain the session information to which the detection message belongs; Determine the target audit process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs; wherein, each session information corresponds to an audit process and an intrusion detection process, and the audit processes and intrusion detection processes corresponding to different session information are different; Send the detection message and the session information to which it belongs to the target audit process; Obtain the first message information returned by the target audit process; wherein, the first message information includes the detection message, the session information to which it belongs, and industrial control protocol elements, and the industrial control protocol elements are obtained by the target audit process through industrial control protocol identification and parsing according to the detection message and the session information to which it belongs; Send the first message information to the target intrusion detection process, so that the target intrusion detection process performs attack intrusion detection according to the detection message, industrial control protocol elements, and a preset attack detection rule library; The determining the target audit process and the target intrusion detection process to which the detection message belongs according to the session information to which the detection message belongs includes: Judge whether the session information to which the detection message belongs is created session information; If it is determined that the session information to which the detection message belongs is created session information, obtain the first process identifier and the second process identifier in the session information to which the detection message belongs; Search for the target audit process among multiple audit processes according to the first process identifier, and search for the target intrusion detection process among multiple intrusion detection processes according to the second process identifier.

2. The method according to claim 1, wherein Wherein, The session information includes the source IP address and the destination IP address to which the detection message belongs; After the judging whether the session information to which the detection message belongs is created session information, the method further includes: If it is determined that the session information to which the detection message belongs is not created, obtain the first total number of current audit processes and the second total number of current intrusion detection processes; Calculate the target audit process to which the detection message belongs according to the first total number, the source IP address and the destination IP address to which the detection message belongs; Calculate the target intrusion detection process to which the detection message belongs according to the second total number, the source IP address and the destination IP address to which the detection message belongs.

3. The method according to claim 2, wherein The judging whether the session information to which the detection message belongs is created session information includes: Search in multiple created session information to find out whether there is session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message; If session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is found in multiple created session information, determine that the session information to which the detection message belongs is created; If session information that is the same as the source IP address, destination IP address, source port, destination port, and transport layer protocol of the detection message is not found in multiple created session information, determine that the session information to which the detection message belongs is not created.

4. The method according to claim 1, characterized in that, After sending the first message to the target intrusion detection process, the method further includes: Obtaining the private data release method in the session information to which the detection message belongs; When the session corresponding to the session information to which the detection message belongs ends, clearing the audit data of the target audit process and the detection data of the target intrusion detection process in the memory according to the private data release method in the session information to which the detection message belongs.

5. The method according to claim 1, characterized in that, The method further includes: Obtaining the heartbeat information of each audit process and intrusion detection process; Judging whether there is a process crash according to the heartbeat information of each audit process and intrusion detection process; If it is determined that there is a process crash, obtaining the detection messages that have been processed by the crashed process and judging the type of the crashed process; If it is determined that the crashed process is an audit process, sending the processed detection messages to the corresponding target intrusion detection process for intrusion detection, updating the identifier of the audit process in the session information to which the detection message belongs to be empty, and clearing the audit data corresponding to the crashed process.

6. The method according to claim 5, characterized in that After judging the type of the crashed process, the method further includes: If it is determined that the crashed process is an intrusion detection process, updating the identifier of the intrusion detection process in the session information to which the detection message belongs to be empty, and releasing the detection message.

7. The method according to claim 5, characterized in that, After it is determined that there is a process crash, the method further includes: Obtaining the unprocessed detection messages of the crashed process and judging the type of the crashed process; If it is determined that the crashed process is an audit process, obtaining the third total number of the audit process, where the third total number is the first total number of the current audit process minus 1; Calculating the updated target audit process to which the unprocessed detection message belongs according to the third total number, the source IP address and the destination IP address to which the unprocessed detection message belongs; Sending the unprocessed detection message to the updated target audit process.

8. The method according to claim 7, wherein After obtaining the unprocessed detection messages of the crashed process and judging the type of the crashed process, the method further includes: If it is determined that the crashed process is an intrusion detection process, obtaining the fourth total number of the intrusion detection process, where the fourth total number is the second total number of the current intrusion detection process minus 1; Calculating the updated target intrusion detection process to which the unprocessed detection message belongs according to the fourth total number, the source IP address and the destination IP address to which the unprocessed detection message belongs; Sending the unprocessed detection message to the updated target intrusion detection process.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Communication message security auditing method in industrial control system

    CN110430187A