An industrial controller network health management method and device, electronic equipment and medium

CN116208370BActive Publication Date: 2026-09-04SUPCON TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211706744.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-29
Publication Date
2026-09-04
Estimated Expiration
2042-12-29

AI Technical Summary

Technical Problem

[0004]但是上述预警系统依然存在以下缺点:需要额外为所有被管理设备添加采集器,配置复杂且成本较高,同时因为额外采集器的添加为控制器引入了新的安全风险,并且该方案仅在控制器发生较大安全故障时才会进行预警,不能对控制器实时运行的安全状态进行评估,因而做不到工业控制器健康度的综合评测和管理

Benefits of technology

可根据工业控制器在网络环境中通信行为,对工业控制器所有状态下的网络健康状态进行综合的实时管理,以保障工业生产安全与信息安全,指导运维人员快速定位安全隐患,降低维护成本。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208370B_ABST
    Figure CN116208370B_ABST
Patent Text Reader

Abstract

The application discloses an industrial controller network health management method and device, electronic equipment and medium, and relates to the technical field of industrial control, comprising monitoring network traffic in an industrial control network; identifying asset types and adding industrial controllers to a list; analyzing industrial controller data packets, recording network anomaly events, bandwidth overrun events, rule violation events and intrusion attack events; comparing event values with preset gradient alarm upper limit values to generate deduction events; calculating total controller health scores within a predetermined time T; performing corresponding processing according to the total controller health scores, generating a health optimization scheme if the health score is higher than the health threshold and is not a full score; and otherwise, performing health warning. The application can comprehensively manage the health status of industrial controllers under all states according to the communication behavior of the industrial controllers in the network, guarantee industrial production safety and information security, guide operation and maintenance personnel to quickly locate safety hazards and reduce maintenance costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control technology, and in particular to a method, apparatus, electronic device, and medium for managing the health of industrial controller networks. Background Technology

[0002] Industrial control systems are widely used in vital industries affecting national welfare and people's livelihoods, such as power, petrochemicals, transportation, municipal engineering, and key manufacturing. Industrial controllers are the core of industrial control systems. With the accelerated digitalization and informatization of industrial control systems, a large number of industrial controllers are exposed to network environments, making them highly vulnerable to remote control or cyberattacks, potentially causing major security incidents.

[0003] To ensure industrial security, in addition to applying necessary boundary protection technologies such as firewalls, it is essential to monitor and provide early warnings in real time for the network health status of industrial controllers—the core of industrial control systems—and to manage them uniformly. This allows for the timely detection of security vulnerabilities in industrial controllers and prompt warnings for those with security risks, thereby ensuring industrial production safety and information security. For example, Chinese invention patent CN112543123A relates to a security protection and early warning system for industrial automatic control systems. This system includes a group-level platform, an inter-plant level platform, a workshop level platform, data collectors, and security protection objects. The security protection objects are the control devices within the industrial network system. The data collectors are connected to the security protection objects to collect information from each object. The workshop level platform is connected to all data collectors within the workshop to receive and display information collected by the data collectors within the workshop area. The inter-plant level platform is connected to all workshop level platforms within the inter-plant to acquire information from each workshop level platform for plant-level analysis, early warning, and decision-making. The group-level platform is connected to all inter-plant level platforms within the group to acquire, display, and monitor information from each inter-plant level platform. By connecting existing systems and equipment to the system of this invention, it is possible to achieve real-time centralized collection, comprehensive analysis, and situational awareness of security log information of enterprise network security equipment.

[0004] However, the above-mentioned early warning system still has the following drawbacks: it requires additional data collectors to be added to all managed devices, which is complex and costly. At the same time, the addition of additional data collectors introduces new security risks to the controller. Furthermore, the solution only issues early warnings when the controller experiences a major security failure, and cannot assess the real-time security status of the controller. Therefore, it cannot achieve comprehensive evaluation and management of the health of industrial controllers.

[0005] In conclusion, in order to ensure the safety of industrial production, it is essential to find a low-cost, low-risk method for industrial controller network health management. Summary of the Invention

[0006] The purpose of this invention is to provide an industrial controller network health management method, device, electronic device, and medium, which can comprehensively manage the network health status of the industrial controller in all states based on the communication behavior of the industrial controller in the network environment, so as to ensure industrial production safety and information security, guide operation and maintenance personnel to quickly locate security risks, and reduce maintenance costs.

[0007] According to a first aspect of the present invention, an industrial controller network health management method is proposed, comprising the following steps: S1: Monitor network traffic in industrial control networks and parse data packets; S2: Use the parsing results to identify the asset type, and add data packets of the asset type "industrial controller" to the corresponding controller list according to their IP address; S3: Performs in-depth analysis on the identified industrial controller data packets, and records network anomaly events, bandwidth overrun events, violation events, and intrusion attack events; S4: Compare the event value with the preset gradient alarm upper limit and generate a corresponding deduction event; S5: Record all deduction events within the predetermined time T and calculate the total health score of the controller within the predetermined time T; S6: Process the controller’s total health score accordingly. If the health score is higher than the health threshold but not full, analyze and generate a health optimization plan. If the health score is lower than the health threshold, issue a health warning.

[0008] Furthermore, monitoring network traffic in the industrial control network specifically includes: Monitor all network traffic in the industrial control network through the mirror port of the core switch of the industrial control network.

[0009] Furthermore, identify the asset types of network traffic, specifically: Parse data packets in network traffic and build an asset list based on IP addresses; then identify the industrial control protocol asset type of the controller through network traffic characteristics to determine whether the asset type is an industrial controller. Network traffic characteristics include communication ports and key fields of data packets.

[0010] Furthermore, the identified industrial controller data packets are parsed to record network anomaly events, bandwidth overrun events, violation events, and intrusion attack events, specifically: The system analyzes the identified industrial controller data packets at the link layer, network layer, transport layer, and application layer. It monitors the controller's network connectivity, data response speed, number of data packet retransmissions, and data packet size in real time from four aspects: controller network status, bandwidth, violations, and intrusion attacks. It also counts bytes per second (BPS) and packets per second (PPS), identifies unauthorized access events and network attack behaviors, and generates network anomaly events, bandwidth overrun events, violation events, and intrusion attack events.

[0011] Furthermore, before comparing the event value with the preset gradient alarm upper limit and generating the corresponding deduction event, the process also includes: For each type of network anomaly, bandwidth overrun, violation, and intrusion attack, preset alarm upper limits for at least two levels and set a deduction value for each level for each event.

[0012] Furthermore, all deduction events within the predetermined time T are recorded, and the total health score of the controller within the predetermined time T is calculated, specifically as follows: Set a maximum score for controller health, obtain all deduction events and their deduction values ​​within a predetermined time T, and subtract all deduction values ​​from the maximum controller health score to obtain the total controller health score within the predetermined time T.

[0013] Furthermore, the health threshold includes a first health threshold and a second health threshold, and the first health threshold is greater than the second health threshold. When determining whether the controller's total health score is higher than the health threshold... If the total health score of the controller is higher than the first health threshold but not full, then the weight of different deduction events of the controller within the predetermined time T is calculated, and a corresponding health optimization plan is generated based on the weight. If the controller's total health score is not higher than the first health threshold, a health reminder will be issued; If the total health score of the controller is not higher than the second health threshold, a health alarm will be issued, and the total health score of the controller will be obtained in real time. The health alarm will not be deactivated until the total health score of the controller is higher than the first health threshold.

[0014] According to a second aspect of the present invention, an industrial controller network health management device is provided, comprising: Monitoring module: Used to monitor network traffic in industrial control networks; Identification module: Used to identify the asset type of network traffic, and add data packets of asset type industrial controller to the corresponding controller list according to IP address; The parsing module parses the identified industrial controller data packets and records network anomaly events, bandwidth overrun events, violation events, and intrusion attack events. Comparison module: Used to compare event values ​​with preset gradient alarm upper limits and generate corresponding deduction events; Processing module: Used to record all deduction events within a predetermined time T and calculate the total health score of the controller within the predetermined time T; Judgment Execution Module: Used to determine whether the controller's total health score is higher than the health threshold. If so, it calculates the weights of different deduction events of the controller within a predetermined time T and generates corresponding health optimization schemes; otherwise, it issues a health warning.

[0015] According to a third aspect of the present invention, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method described in any of the first aspects above.

[0016] According to a fourth aspect of the present invention, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method described in any of the first aspects above.

[0017] This invention provides a method, device, electronic device, and medium for industrial controller network health management, the advantages of which are: Based on the communication behavior of industrial controllers in the network environment, it can comprehensively manage the network health status of industrial controllers in all states in real time, so as to ensure industrial production safety and information security, guide operation and maintenance personnel to quickly locate security risks, and reduce maintenance costs. Attached Figure Description

[0018] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention. In these drawings, similar reference numerals are used to denote similar elements. The drawings described below are some embodiments of the invention, but not all embodiments. Other drawings will be readily available to those skilled in the art based on these drawings without any inventive effort.

[0019] Figure 1 This is a flowchart illustrating an industrial controller network health management method according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the module connection of an industrial controller network health management device according to an embodiment of the present invention. Detailed Implementation

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention and the prior art, the specific implementation methods of the present invention will be described below with reference to the accompanying drawings. Obviously, the accompanying drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings and other implementation methods can be obtained based on these drawings without any creative effort. Furthermore, the design orientation only indicates the relative positional relationship between the components, not the absolute positional relationship.

[0021] Example 1 like Figure 1 As shown, Figure 1 This is a flowchart of an industrial controller network health management method according to an embodiment of the present invention; according to a first aspect of the present invention, an industrial controller network health management method is proposed, comprising the following steps: S1: Monitor network traffic in industrial control networks; Industrial controllers are exposed to network environments. To ensure the security and health of industrial controller networks, it is necessary to obtain network traffic in the network where the industrial controller is located, as the initial management data.

[0022] In this embodiment of the invention, monitoring network traffic in the industrial control network specifically involves: Monitor all network traffic in the industrial control network through the mirror port of the core switch of the industrial control network.

[0023] S2: Identify the asset type of network traffic and add data packets of asset type "industrial controller" to the corresponding controller list according to their IP address; Since the network where the industrial controller is located contains traffic generated not only by the industrial controller's data packets but also by data transmitted from other devices, it is necessary to distinguish all the network traffic acquired, that is, to separate the data packets of the industrial controller from the data packets of other devices, and we only capture the data packets of the industrial controller.

[0024] In this embodiment of the invention, identifying the asset type of network traffic specifically involves: Parse data packets in network traffic and build an asset list based on IP addresses; then identify the industrial control protocol asset type of the controller through network traffic characteristics to determine whether the asset type is an industrial controller. Network traffic characteristics include communication ports and key fields of data packets.

[0025] S3: Parse the identified industrial controller data packets and record network anomaly events, bandwidth overrun events, violation events, and intrusion attack events; Here, the identified industrial controller data packets are parsed, and network anomaly events, bandwidth overrun events, violation events, and intrusion attack events are recorded, specifically: The system analyzes the identified industrial controller data packets at the link layer, network layer, transport layer, and application layer. It monitors the controller's network connectivity, data response speed, number of data packet retransmissions, and data packet size in real time from four aspects: controller network status, bandwidth, violations, and intrusion attacks. It also counts bytes per second (BPS) and packets per second (PPS), identifies unauthorized access events and network attack behaviors, and generates network anomaly events, bandwidth overrun events, violation events, and intrusion attack events.

[0026] in: First aspect: Network status monitoring, 1) Network connectivity issues: When it is detected that the controller does not generate any data packets within a specified time and there are no data packets with the controller as the destination address, it is necessary to probe the network status of the controller. At this time, this device actively sends ARP and ICMP data packets to the controller. If the controller replies, it means that the controller is in a non-working state and the network communication is normal; if the controller does not reply, the controller's network connection is disconnected, and a corresponding network abnormal event is generated. 2) Network response speed: When the controller fails to respond to data packets destined for itself multiple times or when the controller has a large number of retransmitted data packets destined for itself, the controller's network status is abnormal, and a corresponding network status event is generated. The second aspect is bandwidth monitoring. It monitors all data packets flowing through the controller and counts their bytes per second (BPS) and packets per second (PPS). It compares these counts with the corresponding thresholds. If the thresholds are exceeded, a corresponding bandwidth overrun event is generated. Thirdly: violation monitoring, data packet rules and access boundaries can be set, and restrictions on data packet format and length can be set. Access blacklists and whitelists can be set based on information such as IP address, communication port, and communication protocol. If an out-of-bounds behavior occurs, a corresponding violation event will be generated. Fourth aspect: Intrusion behavior monitoring, which can detect common single-packet attacks and denial-of-service attacks launched or suffered by industrial controllers, and generate corresponding intrusion attack events.

[0027] S4: Compare the event value with the preset gradient alarm upper limit and generate a corresponding deduction event; In this embodiment of the invention, before comparing the event value with a preset gradient alarm upper limit and generating a corresponding deduction event, the method further includes: For each type of network anomaly, bandwidth overrun, violation, and intrusion attack, preset alarm upper limits for at least two levels and set a deduction value for each level for each event.

[0028] In other words, different alarm limits are set for each type of event. The value of a certain event detected by the real-time monitoring module is compared with its corresponding upper limit value to generate a corresponding deduction event.

[0029] The upper limit of a gradient alarm refers to the upper limit of an alarm with multiple gradients for the event. Generally, there are at least two upper limit values ​​for alarms with gradients, or it can be set to three upper limit values ​​for alarms with gradients, namely the first upper limit value, the second upper limit value, and the third upper limit value. Here, the first upper limit value is less than the second upper limit value, and the second upper limit value is less than the third upper limit value.

[0030] The deduction value for each gradient can also be set according to the type of industrial controller and the frequency of attacks suffered in the past. For example, the deduction base S for event X. X It has three alarm upper limits. If the actual value of the detected event X is higher than the first alarm upper limit, the health score S is deducted. X , of which S X Set to an integer value on a percentage scale, with a maximum value of 100; if it exceeds the second alarm limit, the health score will be deducted by 1.5SX, and if it exceeds the third alarm limit, the health score will be deducted by 2SX.

[0031] S5: Record all deduction events within the predetermined time T and calculate the total health score of the controller within the predetermined time T; In this embodiment of the invention, all deduction events within a predetermined time T are recorded, and the total health score of the controller within the predetermined time T is calculated, specifically as follows: Set a maximum score for controller health, obtain all deduction events and their deduction values ​​within a predetermined time T, and subtract all deduction values ​​from the maximum controller health score to obtain the total controller health score within the predetermined time T.

[0032] The controller's health score is out of 100, and there is no minimum score requirement for the total health score, meaning the final total health score can be negative.

[0033] S6: Determine whether the controller's total health score is higher than the health threshold. If so, calculate the weight of different deduction events of the controller within a predetermined time T and generate a corresponding health optimization plan; otherwise, issue a health warning.

[0034] In this embodiment of the invention, the health threshold includes a first health threshold and a second health threshold, and the first health threshold is greater than the second health threshold. Therefore: when determining whether the controller's total health score is higher than the health threshold... If the total health score of the controller is higher than the first health threshold, the weights of different deduction events of the controller within a predetermined time T are calculated, and a corresponding health optimization plan is generated. If the controller's total health score is not higher than the first health threshold, a health reminder will be issued; If the total health score of the controller is not higher than the second health threshold, a health alarm will be issued, and the total health score of the controller will be obtained in real time. The health alarm will not be deactivated until the total health score of the controller is higher than the first health threshold.

[0035] This invention provides a health management method for industrial controllers, which can comprehensively manage the health status of industrial controllers in all states based on their communication behavior in a network environment, so as to ensure industrial production safety and information security, guide maintenance personnel to quickly locate safety hazards, and reduce maintenance costs.

[0036] Example 2 like Figure 2 As shown, Figure 2 This is a schematic diagram of the module connection of an industrial controller network health management device according to an embodiment of the present invention; according to a second aspect of the present invention, an industrial controller network health management device is provided, comprising: Monitoring module: Used to monitor network traffic in industrial control networks; Identification module: Used to identify the asset type of network traffic, and add data packets of asset type industrial controller to the corresponding controller list according to IP address; The parsing module parses the identified industrial controller data packets and records network anomaly events, bandwidth overrun events, violation events, and intrusion attack events. Comparison module: Used to compare event values ​​with preset gradient alarm upper limits and generate corresponding deduction events; Processing module: Used to record all deduction events within a predetermined time T and calculate the total health score of the controller within the predetermined time T; Judgment Execution Module: Used to determine whether the controller's total health score is higher than the health threshold. If so, it calculates the weights of different deduction events of the controller within a predetermined time T and generates corresponding health optimization schemes; otherwise, it issues a health warning.

[0037] It is understood that the apparatus provided in the embodiments of the present invention is applicable to the method described in Embodiment 1, and the specific functions of each module can be referred to the above method flow, which will not be repeated here.

[0038] Example 3 According to a third aspect of the present invention, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method described in Embodiment 1 above.

[0039] The electronic device is used to implement the method described in Embodiment 1. The electronic device may include: at least one central processing unit, at least one network interface, a control interface, a memory, and at least one communication bus.

[0040] The communication bus is used to enable communication and information exchange between the various components.

[0041] The network interface may include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0042] The control interface is used to output control operations according to instructions.

[0043] The central processing unit (CPU) may include one or more processing cores. The CPU connects to various parts of the terminal via various interfaces and lines, and executes instructions, programs, code sets, or instruction sets stored in memory, as well as accessing data stored in memory, to perform various functions of the terminal and process data according to the method described in Embodiment 1.

[0044] The memory may include random access memory (RAM) or read-only memory. Optionally, the memory may include non-transitory computer-readable storage medium. The memory can be used to store instructions, programs, code, code sets, or instruction sets. The memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the methods described in Embodiment 1 above, etc.; the data storage area may store data involved in the various method embodiments above, etc.

[0045] A fourth aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in Embodiment 1 above. The computer-readable storage medium may include, but is not limited to, any type of disk, including floppy disks, optical disks, DVDs, CD-ROMs, microdrives, as well as magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, magnetic cards or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.

[0046] This invention provides an industrial controller health management method, device, electronic device, and medium. It can comprehensively manage the health status of the industrial controller in all states based on the communication behavior of the industrial controller in the network environment, so as to ensure industrial production safety and information security, guide operation and maintenance personnel to quickly locate safety hazards, and reduce maintenance costs.

[0047] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0048] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0049] In the several embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some service interface; the indirect coupling or communication connection between devices or units may be electrical or other forms.

[0050] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0051] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0052] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0053] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.

[0054] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

[0055] The foregoing description is merely an exemplary embodiment of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Those skilled in the art will readily conceive of embodiments of this disclosure upon considering the specification and practicing the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described herein. The specification and embodiments are to be considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.

Claims

1. A method for health management of industrial controller networks, characterized in that, include: S1: Monitor all network traffic in the industrial control network and parse data packets; S2: Use the parsing results to identify the asset type, and add data packets of the asset type "industrial controller" to the corresponding controller list according to their IP address; distinguish all the acquired network traffic, that is, separate the data packets of industrial controllers from data packets of other devices; Identifying asset types involves: parsing data packets in network traffic and building an asset list based on IP addresses; then identifying the industrial control protocol asset type of the controller through network traffic characteristics to determine whether the asset type is an industrial controller. S3: Parse the identified industrial controller data packets and record network anomaly events, bandwidth overrun events, violation events, and intrusion attack events; When executing step S3, the specific steps are as follows: the identified industrial controller data packets are parsed at the link layer, network layer, transport layer, and application layer. The controller's network connectivity, data response speed, number of data packet retransmissions, and data packet size are monitored in real time from four aspects: controller network status, bandwidth, and violations and intrusion attacks. The bytes per second (BPS) and packets per second (PPS) are counted. Unauthorized access events and network attack behaviors are identified, and network abnormal events, bandwidth overrun events, violation events, and intrusion attack events are generated. S4: Compare the event value with the preset gradient alarm upper limit and generate a corresponding deduction event; S5: Record all deduction events within the predetermined time T and calculate the total health score of the controller within the predetermined time T; S6: Process the controller's total health score accordingly. If the health score is higher than the health threshold, analyze and generate a health optimization plan. If the health score is lower than the health threshold, a health warning will be issued; The health threshold includes a first health threshold and a second health threshold, and the first health threshold is greater than the second health threshold. When determining whether the controller's total health score is higher than the health threshold... If the controller's total health score is higher than the first health threshold but not full, then the weights of different deduction events of the controller within a predetermined time T are calculated, and corresponding health optimization schemes are generated. If the controller's total health score is not higher than the first health threshold, a health reminder will be issued; If the controller's total health score is not higher than the second health threshold, a health alarm will be triggered.

2. The industrial controller network health management method according to claim 1, characterized in that, Before comparing the event value with the preset gradient alarm upper limit and generating the corresponding deduction event, the process also includes: For each type of network anomaly, bandwidth overrun, violation, and intrusion attack, preset alarm upper limits for at least two levels and set a deduction value for each level for each event.

3. The industrial controller network health management method according to claim 1, characterized in that, All deduction events within the predetermined time T are recorded, the total health score of the controller within the predetermined time T is calculated, and a solution is recommended, specifically as follows: Set a maximum score for controller health, obtain all deduction events and their deduction values ​​within a predetermined time T, subtract all deduction values ​​from the maximum controller health score to obtain the total controller health score within the predetermined time T, and recommend solutions based on different scores and deduction event weights.

4. An industrial controller network health management device, characterized in that, include: Monitoring module: Used to monitor network traffic in industrial control networks and parse data packets; Identification module: Used to identify asset type using parsing results, add data packets of asset type industrial controller to the corresponding controller list according to IP address, and distinguish all network traffic acquired, that is, separate data packets of industrial controller from data packets of other devices; Identifying asset types involves: parsing data packets in network traffic and building an asset list based on IP addresses; then identifying the industrial control protocol asset type of the controller through network traffic characteristics to determine whether the asset type is an industrial controller. The parsing module is used to parse the identified industrial controller data packets and record network anomaly events, bandwidth overrun events, violation events, and intrusion attack events. When the parsing module is working, it specifically performs the following: parsing of the identified industrial controller data packets at the link layer, network layer, transport layer, and application layer; and monitors the controller's network connectivity, data response speed, number of data packet retransmissions, and data packet size in real time from four aspects: controller network status, bandwidth, and violations and intrusion attacks. It also counts the bytes per second (BPS) and packets per second (PPS), identifies unauthorized access events and network attack behaviors, and generates network anomaly events, bandwidth overrun events, violation events, and intrusion attack events. Comparison module: Used to compare event values ​​with preset gradient alarm upper limits and generate corresponding deduction events; Processing module: Used to record all deduction events within a predetermined time T and calculate the total health score of the controller within the predetermined time T; Judgment Execution Module: Used to perform corresponding processing based on the total health score of the controller. If the health score is higher than the health threshold, a health optimization plan is generated. If the health score is lower than the health threshold, a health warning will be issued; The health threshold includes a first health threshold and a second health threshold, and the first health threshold is greater than the second health threshold. When determining whether the controller's total health score is higher than the health threshold... If the controller's total health score is higher than the first health threshold but not full, then the weights of different deduction events of the controller within a predetermined time T are calculated, and corresponding health optimization schemes are generated. If the controller's total health score is not higher than the first health threshold, a health reminder will be issued; If the controller's total health score is not higher than the second health threshold, a health alarm will be triggered.

5. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements an industrial controller network health management method as described in any one of claims 1 to 3.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements an industrial controller network health management method as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Safety protection and early warning system of industrial automatic control system

    CN112543123A

  • Method and system for distributing cloud computing resources

    CN103164279A

  • Server health degree evaluation method

    CN106776214A

  • Method and apparatus for evaluating security health index of industrial control network

    CN109495502A