An intelligent network security situation monitoring and early warning platform for industrial control systems
By constructing an intelligent network security situation monitoring and early warning platform for industrial control systems, integrating real-time monitoring, alarm fusion, and threat tracing functions, the platform solves the security monitoring problem of power industrial control systems in complex environments and realizes the system's real-time security management and early warning capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE
- Filing Date
- 2022-11-21
- Publication Date
- 2026-04-28
AI Technical Summary
Existing technologies are unable to effectively monitor and provide early warning of cybersecurity threats to power industrial control systems, resulting in serious security risks for these systems in complex attack environments.
An intelligent network security situation monitoring and early warning platform for industrial control systems was designed, comprising a device layer, a data acquisition layer, a data storage layer, an application service layer, and a display layer. It integrates real-time monitoring of network security events, deep fusion of heterogeneous discrete alarms, security threat auditing and tracing, and automatic network topology analysis, and utilizes artificial intelligence for correlation analysis and visualization.
It enables real-time network security monitoring and early warning of power industrial control systems, meets the requirements of manageability, controllability and traceability in cyberspace, and improves system security and management efficiency.
Smart Images

Figure CN116257021B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of early warning technology for industrial control systems, and in particular relates to an intelligent network security situation monitoring and early warning platform for industrial control systems. Background Technology
[0002] With the rapid development of power automation technology, industrial control systems (ICS) are increasingly adopting common protocols / standards, general-purpose hardware / software, and network equipment. The physical isolation and software / hardware exclusivity of ICS are gradually being broken down. While the intelligence of ICS has improved production and management efficiency, it has also created opportunities for malicious attackers. As the most important control system in the power industry, ICS have faced unprecedented threats in a highly competitive security environment, becoming targets for attacks and infiltration. Faced with increasingly sophisticated, complex, and mature attack techniques targeting power ICS, the security threats to power ICS are becoming increasingly severe.
[0003] Therefore, effectively monitoring threats to power grid industrial control systems and promptly identifying potential security issues has become an urgent problem to be solved. Summary of the Invention
[0004] The purpose of this invention is to provide an intelligent network security situation monitoring and early warning platform for industrial control systems, which is a network security monitoring and early warning solution for power industrial control systems. It integrates real-time monitoring and analysis application technology for network security events, deep fusion of heterogeneous discrete alarms, security threat audit and tracing, and automatic network topology analysis, so as to meet the real-time monitoring and operation requirements of network space that are manageable, controllable, and traceable, and solve the problems of existing technologies.
[0005] This invention provides an intelligent network security situation monitoring and early warning platform for industrial control systems, comprising: a device layer, a data acquisition layer, a data storage layer, an application service layer, and a display layer; wherein:
[0006] The device layer includes: an industrial control host module, a network device module, a security device module, and a third-party system; the device layer is used to monitor and provide early warnings for assets, which are the foundation for conducting business and the core of security protection;
[0007] The data acquisition layer includes a data proxy, a traffic probe, and a log collector. This layer is used to identify log, data, and traffic information from various security control nodes in the system network, and to collect and upload this information uniformly. It is used for raw packet collection, protocol parsing, preliminary attack detection, and information aggregation and statistics. Protocol parsing includes the parsing of the TCP / IP protocol stack and in-depth parsing of industrial control protocols.
[0008] The data storage layer includes a memory key-value database cache, a relational database, a real-time data analysis system, and a distributed big data processing module; the data storage layer adopts distributed storage.
[0009] The application service layer includes an asset management module, a vulnerability management module, a threat analysis module, a workbench, a knowledge base, a data source management module, an alarm management module, a report management module, an equipment management module, and a system management module. It is used to leverage artificial intelligence for correlation analysis, security modeling, analysis, and early warning. It integrates log message parsing results from the data acquisition layer, summarizes statistical information, and performs various security detections, including industrial control network communication behavior modeling, TCP / IP anomaly detection, industrial control command anomaly detection, industrial control critical event detection, network storm detection, network session anomaly detection, and threshold-based detection. It also supports detection based on user-defined rules.
[0010] The presentation layer includes operation and maintenance monitoring, asset statistics, risk display, and industrial network topology, which are used to abstract data into graphs and provide a visual display for the final safe operation.
[0011] Preferably, the industrial control host module of the equipment layer includes: DCS operator station, DCS engineer station, DCS historical station, DCS OPC, DCS server, SIS interface machine, SIS database server, DEH server, DEH interface machine, auxiliary operator station, auxiliary control operator station, auxiliary control server, auxiliary network interface machine, auxiliary machine 6KV server, and electricity metering server.
[0012] Preferably, the network device module of the device layer includes a SIS core switch, a DCS switch, an auxiliary control switch, an electricity metering switch, a network-side real-time switch, and a network-side non-real-time switch.
[0013] Preferably, the security device module of the device layer includes an isolation gateway, industrial log auditing, and industrial network auditing.
[0014] Preferably, the third-party system in the device layer is an intelligent video surveillance system.
[0015] Preferably, the data agent in the data acquisition layer is deployed on the industrial control host to collect host information and forward it to the log collector; the traffic probe is used to collect traffic data, connects to the switch mirror port, and forwards the data to the platform after preliminary parsing; the log collector is used to collect log information forwarded by the data agent, network devices, and security devices, and forwards it to the platform after preliminary processing; the data collected by the monitoring and early warning platform is divided into two main categories: traffic data and log data, which are collected separately by the data agent and the traffic log collector; wherein the data agent is deployed on the industrial control host to collect host information; the traffic log collector collects traffic data and log information forwarded by the data agent, network devices, and security devices, and forwards it to the platform after preliminary processing.
[0016] Preferably, the asset management module of the application service layer includes asset discovery, asset restructuring, asset retrieval, and asset tagging;
[0017] The vulnerability management module of the application service layer includes vulnerability assessment, classification monitoring, query statistics, and chart display.
[0018] The threat analysis module of the application service layer includes rule configuration, correlation analysis, source tracing and evidence collection, and modeling and prediction.
[0019] The application service layer's workbench includes user login, preset interfaces, scene entry points, and personalized settings;
[0020] The knowledge base of the application service layer includes an industrial control system vulnerability database, an industrial control system protocol database, an audit rule database, and a threat intelligence database;
[0021] The data source management module of the application service layer includes log access, status display, data proxy management, and collector management;
[0022] The alarm management module of the application service layer includes alarm display, alarm query, alarm handling, and emergency plans;
[0023] The report management module of the application service layer includes template management, task list, task management, and monthly security report;
[0024] The device management module of the application service layer includes a device list, statistical analysis, device details, and configuration backup.
[0025] The system management module of the application service layer includes permission management, role classification, system configuration, and log backup.
[0026] Preferably, the data storage layer is used for data storage and processing. The platform database and data processing tools use a relational database to store structured data, and an in-memory key-value database cache serves as a high-speed cache for the relational database. The distributed big data processing module is used to store and process unstructured data, and the real-time analysis system is used to store and process semi-structured data. Specifically, the relational database is used to store platform analysis results, the in-memory key-value database is a high-performance non-relational database based on memory, and serves as a high-speed cache for storing "hot" data. The real-time analysis system can be used for log file analysis and includes three components: a log collection and processing component, a distributed full-text search and analysis engine, and a data visualization component. The log collection and processing component collects and formats logs, outputting them to the distributed full-text search and analysis engine for log retrieval and analysis. The data visualization component provides a visual interface. The distributed big data processing module can be used to process unstructured data and includes multiple components such as a distributed message queue, a distributed coordination service, an in-memory computing framework, a data warehouse tool, a columnar database, and a log collection and transmission tool, suitable for offline processing of large amounts of data. The in-memory computing framework is a computing framework that can embed algorithms and be used in conjunction with machine learning.
[0027] Preferably, the deployment architecture of the monitoring and early warning platform includes: the situational awareness platform is planned to be deployed in Security Zone II, with a separate network and independent deployment.
[0028] Preferably, the data collection objects of the monitoring and early warning platform include: intelligent video surveillance system, DCS, SIS, host of auxiliary control system, network equipment and security equipment at the boundary.
[0029] The platform provided by this invention has the following beneficial technical effects:
[0030] The intelligent network security situation monitoring and early warning platform for industrial control systems provides a network security monitoring and early warning solution for power industrial control systems. It integrates real-time monitoring and analysis application technologies such as real-time monitoring of network security events, deep fusion of heterogeneous discrete alarms, security threat audit and tracing, and automatic network topology analysis to meet the real-time monitoring and operation requirements of network space that are manageable, controllable, and traceable. Attached Figure Description
[0031] Figure 1 This is a platform structure diagram illustrating a preferred embodiment of the present invention. Detailed Implementation
[0032] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.
[0033] like Figure 1As shown, this embodiment provides an intelligent network security situation monitoring and early warning platform for industrial control systems, including:
[0034] The technical structure model is abstracted and divided into six layers, from lowest to highest: device layer, data acquisition layer, data storage layer, application service layer, and presentation layer; among which:
[0035] The device layer includes: an industrial control host module, a network device module, a security device module, and a third-party system; the device layer is used to monitor and provide early warnings for assets, which are the foundation for conducting business and the core of security protection;
[0036] The data acquisition layer includes a data proxy, a traffic probe, and a log collector; the data acquisition layer is used to identify the information of logs, data, and traffic of each security control node in the system network, and to collect and upload them in a unified manner; it is used for the collection of raw packets, protocol parsing (including the parsing of the TCP / IP protocol stack and the deep parsing of industrial control protocols), preliminary attack detection, and information aggregation and statistics.
[0037] The data storage layer includes a memory key-value database cache, a relational database, a real-time data analysis system, and a distributed big data processing module; the data storage layer adopts distributed storage to reduce the data storage and processing pressure of the top-level layer.
[0038] The application service layer includes an asset management module, a vulnerability management module, a threat analysis module, a workbench, a knowledge base, a data source management module, an alarm management module, a report management module, a device management module, and a system management module. It is used to leverage artificial intelligence for correlation analysis, security modeling, analysis, and early warning. It integrates log message parsing results from the data acquisition layer, summarizes statistical information, and performs various security detections such as industrial control network communication behavior modeling, TCP / IP anomaly detection, industrial control command anomaly detection, industrial control critical event detection, network storm detection, network session anomaly detection, and threshold-based detection. It also supports detection based on user-defined rules.
[0039] The presentation layer includes operation and maintenance monitoring, asset statistics, risk display, and industrial network topology, which are used to abstract data into graphs and provide a visual display for the final safe operation.
[0040] In a preferred embodiment, the industrial control host module of the equipment layer includes: DCS operator station, DCS engineer station, DCS historical station, DCS OPC, DCS server, SIS interface machine, SIS database server, DEH server, DEH interface machine, auxiliary operator station, auxiliary control operator station, auxiliary control server, auxiliary network interface machine, auxiliary machine 6KV server, and electricity metering server.
[0041] In a preferred embodiment, the network device module of the device layer includes a SIS core switch, a DCS switch, an auxiliary control switch, an electricity metering switch, a network-side real-time switch, and a network-side non-real-time switch.
[0042] In a preferred embodiment, the security device module of the device layer includes an isolation gateway, industrial log auditing, and industrial network auditing.
[0043] In a preferred embodiment, the third-party system in the device layer is an intelligent video surveillance system.
[0044] In a preferred implementation, the data agent in the data acquisition layer is deployed on the industrial control host to collect host information and forward it to the log collector; the traffic probe is used to collect traffic data, connects to the switch mirror port, and forwards the data to the platform after preliminary parsing; the log collector is used to process log information forwarded by the data agent, network devices, and security devices, and forwards it to the platform after preliminary processing. The platform collects a large amount of data from diverse sources. If no acquisition devices are used and data is collected only through the platform protocol, the data collection will be incomplete and may affect platform performance. Therefore, in principle, a certain number of collectors and data agents should be deployed to cooperate with the platform for data collection.
[0045] The monitoring and early warning platform collects data in two main categories: traffic data and log data. The data is collected through a data proxy and a traffic log collector. The data proxy is deployed on the industrial control host to collect host information. The traffic log collector collects traffic data and log information forwarded by the data proxy, network devices, and security devices. After preliminary processing, the data is forwarded to the platform.
[0046] In this embodiment:
[0047] (1) Data agent, also known as data collection script, is used to collect indicators of Windows and Linux systems, obtain device login logs and operation logs, and obtain device status (online or offline) using heartbeat signal data such as CPU and memory. It only collects data and does not control it, making it a lightweight data collection software. Data agent can be distributed on multiple hosts, actively collects logs and other relevant information from plugins, and then sends them to the situational awareness platform or log collector after unifying the format.
[0048] (2) The log collector, as a data collection device between the data agent and the platform, can reduce the platform's data collection pressure. After the data is merged by the collector, the platform can further perform centralized correlation analysis on this data, analyze vulnerabilities and abnormal behaviors, form security event descriptions, and perform attack detection and threat alerts.
[0049] The main functions of the log collector are as follows:
[0050] A. Normalize the log data. For example, classify the data according to data warehouse tags, merge data fields, unify fields from different vendors, fill in null and invalid values, and transform the raw logs into structured data.
[0051] B. Data field enhancement. For example, enhancing and expanding the IP string to include information such as the corresponding region, city, province, and carrier, or parsing a specified field as time.
[0052] C. Edge computing. The segmentation and distribution of log streams, traffic, and data proxy service data reduces redundant data and saves bandwidth costs.
[0053] D. Data forwarding. It has multiple built-in sending endpoints (sending to local files, distributed full-text search and analysis engine, distributed message queue, etc.) to compress and forward data to the platform.
[0054] (3) The main functions of the flow probe are as follows:
[0055] A. Capture data packets. All network data packets are captured and buffered to disk;
[0056] B. Traffic Metadata Parsing. This involves parsing, transforming, and storing the metadata in traffic data packets.
[0057] In a preferred embodiment, the asset management module of the application service layer includes asset discovery, asset restructuring, asset retrieval, and asset tagging;
[0058] The vulnerability management module of the application service layer includes vulnerability assessment, classification monitoring, query statistics, and chart display.
[0059] The threat analysis module of the application service layer includes rule configuration, correlation analysis, source tracing and evidence collection, and modeling and prediction.
[0060] The application service layer's workbench includes user login, preset interfaces, scene entry points, and personalized settings;
[0061] The knowledge base of the application service layer includes an industrial control system vulnerability database, an industrial control system protocol database, an audit rule database, and a threat intelligence database;
[0062] The data source management module of the application service layer includes log access, status display, data proxy management, and collector management;
[0063] The alarm management module of the application service layer includes alarm display, alarm query, alarm handling, and emergency plans;
[0064] The report management module of the application service layer includes template management, task list, task management, and monthly security report;
[0065] The device management module of the application service layer includes a device list, statistical analysis, device details, and configuration backup.
[0066] The system management module of the application service layer includes permission management, role classification, system configuration, and log backup.
[0067] In a preferred embodiment, the data storage layer is used for data storage and processing. The platform database and data processing tools adopt a mainstream configuration: a relational database is used to store structured data, an in-memory key-value database cache serves as a high-speed cache for the relational database, a distributed big data processing module is used to store and process unstructured data, and a real-time analysis system is used to store and process semi-structured data. Specifically, the relational database is used to store platform analysis results, the in-memory key-value database is a high-performance non-relational database that can be used as a high-speed cache to store "hot" data, and the real-time analysis system is used for log file analysis. It includes three components: a log collection and processing component, a distributed full-text search and analysis engine, and a data visualization component. The log collection and processing component collects and formats logs, outputting them to the distributed full-text search and analysis engine for log retrieval and analysis. The data visualization component provides a visual interface. The distributed big data processing module can be used to process unstructured data and includes multiple components such as a distributed message queue, a distributed coordination service, an in-memory computing framework, data warehouse tools, a columnar database, and log collection and transmission tools, suitable for offline processing of large amounts of data. The in-memory computing framework is a computing framework that can embed algorithms and be used in conjunction with machine learning.
[0068] As a preferred implementation, the deployment architecture of the monitoring and early warning platform includes: the situational awareness platform is planned to be deployed in Security Zone II, with a separate network and independent deployment. The reason for deploying it in Zone II is that the platform's data sources are concentrated in Security Zones I and II, and these two zones have fewer security devices and lower security, while the management information zone has more security devices deployed and relatively complete protection, eliminating the need for repeated data collection and analysis.
[0069] In a preferred embodiment, the data collection objects of the monitoring and early warning platform include: intelligent video surveillance system, DCS, SIS, host of auxiliary control system, network equipment and security equipment at the boundary.
[0070] In this embodiment, the platform's technology includes:
[0071] I. Key Application Technologies of Intelligent Network Security Situation Monitoring and Early Warning Solution for Power Control Systems
[0072] First, a security protection strategy for power industrial control systems and an automatic verification and early warning technology for software versions are proposed and developed to address the problems of traditional security verification methods not supporting power industrial control software and dedicated security equipment, and the lack of online management means for software versions. Second, a collaborative control method for dynamic perception and threat handling of abnormal behavior applicable to industrial control terminals is proposed, and a network security monitoring device suitable for monitoring industrial control terminals is developed to solve the problem of real-time security monitoring of heterogeneous industrial control terminals and achieve full coverage of industrial control terminal security monitoring. Finally, a dynamically expandable method for parsing industrial control communication protocols and monitoring abnormal behavior is proposed, and a network security monitoring device suitable for monitoring industrial control network traffic is determined to solve the problem of parsing personalized and differentiated industrial control communication protocols on-site, and to achieve real-time tracking and early warning of industrial control business behavior state machines.
[0073] II. Functional Analysis of Network Security Monitoring and Early Warning Solutions for Power Control Systems
[0074] The network security monitoring platform has local management functions, including asset management, display of security operation status, support for local storage of alarm content, and support for retrieval and query. It monitors the operation of security monitoring devices, including power supply, CPU utilization, memory utilization, hard disk storage space, communication link status, user login, and abnormal operations. It supports the management of alarm generation policies, which can be modified remotely. The network security monitoring devices provide services to the network security management platform in the form of service proxies. Simultaneously, it has a clock synchronization function, ensuring that the security monitoring platform's time is strictly synchronized with the plant's internal control layer monitoring system to guarantee smooth data acquisition, security analysis, and alarm processing. It also has network traffic analysis capabilities, capturing traffic from switch mirror ports for protocol analysis, and providing real-time monitoring and early warning of abnormal traffic and behavior. Furthermore, it has antivirus management functions, providing an antivirus client engine and enabling remote management of the virus database through the network security management platform, further improving the plant's security protection level.
[0075] III. Threat Identification and Monitoring of Power Control Protocols
[0076] Currently, power industrial control systems face increasingly serious threats. Security threat monitoring primarily targets and analyzes the security issues of intelligent terminals in power consumption acquisition systems and distribution automation terminals. The system analyzes the threats they face and their vulnerabilities, assesses the potential harm caused by security incidents, and verifies its security threat monitoring and analysis capabilities by combining them with actual attack methods. The platform mainly focuses on data acquisition, parsing, analysis, security monitoring, and alarms for control equipment, network communication traffic, I / O status, DCS engineering stations, DCS operator stations, network devices, and security devices in industrial control systems. The system is based on a modular, layered design principle, including a data acquisition layer, a big data storage layer, a big data analysis layer, a monitoring business layer, and a data presentation layer. Big data storage primarily parses and formats the acquired data for further storage and analysis. The big data analysis layer constructs a categorized database through data pre-analysis and stores it based on cloud data. It utilizes big data analytics to extract, preprocess, and integrate data, providing capabilities such as complete analysis of control commands and configuration programs of distributed control systems, anomaly analysis of system and network traffic, attack correlation analysis, and time-series analysis of system status. The monitoring service layer provides security monitoring functions for distributed control systems, including abnormal traffic monitoring, virus attack monitoring, communication behavior monitoring, bus access monitoring, system load monitoring, status parameter monitoring, control signal monitoring, DCS configuration monitoring, and DCS data and control command monitoring. The data visualization layer provides unified and visualized security posture display, real-time monitoring, monitoring alarms, source tracing analysis, and statistical reports. Industrial network field monitoring devices are used to collect and analyze industrial Ethernet traffic, bus field monitoring devices are used to collect and analyze traffic on typical fieldbuses, and control signal field monitoring devices are used to directly collect and analyze signals on I / O signal lines. All collected real-time data is stored in a database cluster for analysis by the central anomaly monitoring platform.
[0077] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if these modifications and modifications of the invention fall within the scope of the claims and their equivalents, the invention is also intended to include these modifications and modifications.
Claims
1. An intelligent network security situation monitoring and early warning platform for industrial control systems, characterized in that, include: The system comprises: device layer, data acquisition layer, data storage layer, application service layer, and presentation layer; among which: The device layer includes: an industrial control host module, a network device module, a security device module, and a third-party system; the device layer is used to monitor and provide early warnings for assets, which are the foundation for conducting business and the core of security protection; The data acquisition layer includes a data proxy, a traffic probe, and a log collector. This layer is used to identify log, data, and traffic information from various security control nodes in the system network, and to collect and upload this information uniformly. It is used for raw packet collection, protocol parsing, preliminary attack detection, and information aggregation and statistics. Protocol parsing includes the parsing of the TCP / IP protocol stack and in-depth parsing of industrial control protocols. The data storage layer includes a memory key-value cache, a relational database, a real-time data analysis system, and a distributed big data processing module; the data storage layer adopts distributed storage. The application service layer includes an asset management module, a vulnerability management module, a threat analysis module, a workbench, a knowledge base, a data source management module, an alarm management module, a report management module, an equipment management module, and a system management module. It is used to leverage artificial intelligence for correlation analysis, security modeling, analysis, and early warning. It integrates log message parsing results from the data acquisition layer, summarizes statistical information, and performs various security detections, including industrial control network communication behavior modeling, TCP / IP anomaly detection, industrial control command anomaly detection, industrial control critical event detection, network storm detection, network session anomaly detection, and threshold-based detection. It also supports detection based on user-defined rules. The presentation layer includes operation and maintenance monitoring, asset statistics, risk display, and industrial network topology, which are used to abstract data into graphs and provide a visual display for the final safe operation.
2. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The industrial control host module of the equipment layer includes: DCS operator station, DCS engineer station, DCS historical station, DCS OPC, DCS server, SIS interface machine, SIS database server, DEH server, DEH interface machine, auxiliary operator station, auxiliary control operator station, auxiliary control server, auxiliary network interface machine, auxiliary machine 6KV server, and electricity metering server.
3. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The network device modules in the device layer include SIS core switches, DCS switches, auxiliary control switches, electricity metering switches, real-time switches on the network side, and non-real-time switches on the network side.
4. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The security device module in the device layer includes an isolation gateway, industrial log auditing, and industrial network auditing.
5. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The third-party system in the device layer is an intelligent video surveillance system.
6. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The data agent in the data acquisition layer is deployed on the industrial control host, collects host information, and forwards it to the log collector; Traffic probes are used to collect traffic data. They are connected to the mirror port of the switch and the data is initially parsed before being forwarded to the platform. The log collector is used to collect log information forwarded by proxy programs, network devices, and security devices, and forwards it to the platform after preliminary processing; the data collected by the monitoring and early warning platform is divided into two main categories: traffic data and log data, which are collected separately through data proxy and traffic log collector; The data agent is deployed on the industrial control host to collect host information; The traffic log collector collects traffic data and log information forwarded by proxy programs, network devices, and security devices, and forwards it to the platform after preliminary processing.
7. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The asset management module of the application service layer includes asset discovery, asset restructuring, asset retrieval, and asset tagging; The vulnerability management module of the application service layer includes vulnerability assessment, classification monitoring, query statistics, and chart display. The threat analysis module of the application service layer includes rule configuration, correlation analysis, source tracing and evidence collection, and modeling and prediction. The application service layer's workbench includes user login, preset interfaces, scene entry points, and personalized settings; The knowledge base of the application service layer includes an industrial control system vulnerability database, an industrial control system protocol database, an audit rule database, and a threat intelligence database; The data source management module of the application service layer includes log access, status display, proxy management, and collector management; The alarm management module of the application service layer includes alarm display, alarm query, alarm handling, and emergency plans; The report management module of the application service layer includes template management, task list, task management, and monthly security report; The device management module of the application service layer includes a device list, statistical analysis, device details, and configuration backup. The system management module of the application service layer includes permission management, role classification, system configuration, and log backup.
8. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The data storage layer is used for data storage and processing. The platform database and data processing tools use a relational database to store structured data, with an in-memory key-value database serving as a high-speed cache for this relational database. The distributed big data processing module is used to store and process unstructured data, and the real-time log collection, retrieval, and visualization system is used to store and process semi-structured data. The relational database stores platform analysis results; the in-memory key-value database is a high-performance, in-memory non-relational database used as a high-speed cache to store "hot" data; the real-time log collection, retrieval, and visualization system can be used for log file analysis, and includes a log collection and processing component, a distributed full-text search and analysis engine, and a data visualization component; the log collection and processing component collects and formats logs, outputting them to the distributed full-text search and analysis engine for log retrieval and analysis; the data visualization component provides a visual interface; the distributed big data processing module processes unstructured data, and includes multiple components such as a distributed message queue, a distributed coordination service, an in-memory computing framework, data warehouse tools, a columnar database, and log collection and transmission tools, suitable for offline processing of massive amounts of data; the in-memory computing framework can serve as a computing engine, embedding algorithms and working in conjunction with machine learning.
9. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The deployment architecture of the monitoring and early warning platform includes: the situational awareness platform is planned to be deployed in Security Zone II, with a separate network and independent deployment.
10. The intelligent network security situation monitoring and early warning platform for industrial control systems according to claim 1, characterized in that, The data collection objects of the monitoring and early warning platform include: intelligent video surveillance system, DCS, SIS, host of auxiliary control system, network equipment and security equipment at the boundary.
Citation Information
Patent Citations
Safety production management and control device, system and method
CN107885170A
Heat supply management and control integrated platform system with network security protection function and application
CN113359625A