An industrial internet virus prevention and control method

By constructing an industrial internet network model and optimizing the SIR model, and combining strategies such as expanding the connectivity surface, enhancing immunity, and prioritizing importance, the problems of the concealment of virus intrusions in the industrial internet and the limitations of traditional antivirus products have been solved, achieving precise suppression of virus propagation and improvement of network security.

CN116318828BActive Publication Date: 2026-04-17BEIHANG UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIHANG UNIV
Filing Date
2023-01-29
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In the Industrial Internet, virus intrusions are highly covert, and traditional antivirus products have significant limitations in the use of industrial control systems, resulting in insufficient network security and making it easy to cause widespread failures and losses.

Method used

An industrial internet network model is constructed. By assessing node importance and establishing a composite virus propagation model, a network model-based prevention and remediation strategy is adopted, including expanding the connectivity, enhancing immunity, increasing load capacity, isolation immunity, and priority-based control methods. The SIR model is optimized to simulate virus propagation for precise suppression and remediation.

Benefits of technology

It effectively simulates virus transmission, reduces the probability of virus transmission, improves network security and reliability, reduces the scope of fault propagation, and reduces economic losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318828B_ABST
    Figure CN116318828B_ABST
Patent Text Reader

Abstract

This invention relates to a method for preventing and controlling viruses in the Industrial Internet, with the following specific steps: Step 1: Constructing a network topology model of the Industrial Internet; Step 2: Evaluating the importance of nodes and classifying the importance level of each node in the network; Step 3: Establishing a composite virus propagation model, with nodes having ten states; Step 4: Analyzing the composite virus propagation model; Step 5: Constructing virus propagation prevention and remediation control strategies. This invention constructs an Industrial Internet network model based on a network model construction method, analyzes the model space and structural characteristics, evaluates the importance of the Industrial Internet network model, analyzes the impact of relevant parameters on virus propagation, simulates the virus propagation process within the industrial control network, prevents further damage to the Industrial Internet caused by fault propagation, and facilitates timely post-incident network repair work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial internet technology, specifically to a method for preventing and controlling industrial internet viruses. Background Technology

[0002] In the analysis and research of complex systems, complex networks, as an abstract research method, can abstractly describe complex systems. Complex networks are networks that exhibit high complexity and are an abstraction of complex systems.

[0003] In the modeling of complex networks, different network generation methods can generate various forms of basic networks. Erdos and Renyi first proposed the Stochastic Network Model (ER model), which consists of N nodes connected by edges with a certain probability, and all nodes follow a Pascal distribution. Watts and Strogatz proposed the Small World Network Model (WS model), characterized by a small average path length. The network consists of multiple nodes forming a ring, with each node connected to a certain number of nodes on its sides and forming long-range connections with distant nodes with a certain probability.

[0004] One important approach to studying virus propagation in networks is to establish a relatively universal virus propagation model based on the fundamental characteristics of networks. Network viruses and infectious disease viruses share many similarities in their propagation mechanisms, so infectious disease virus propagation models can be introduced to study network virus propagation models. Cohen et al. first proposed a novel modeling method based on infectious disease dynamics, which mainly studies the propagation patterns of viruses but did not establish a specific virus propagation model. Kephart and White et al. established a partial network virus propagation model based on the infectious disease dynamics SIS propagation model and described the characteristics of network virus propagation, where S represents the susceptible state and I represents the infected state. Valdez et al., combining antivirus software and other protective measures, added a recoverable state R (Recovered) with immunity to the SIS propagation model. This means that when a node is in the recoverable state R, it will not be reinfected or transmit the virus; this model is called the SIR model.

[0005] External failures caused by virus transmission leading to node infection are usually analyzed using infectious disease virus transmission models based on the SIR model, while internal failures induced by virus transmission are usually analyzed using failure propagation models such as load-capacity and Cascade.

[0006] Researching virus prevention and control strategies can effectively prevent and control the spread of viruses in the Industrial Internet, representing an advancement in the study of virus propagation mechanisms in the Industrial Internet. The first step in researching virus propagation and related issues in the Industrial Internet is to model the research object.

[0007] Ren et al. explored the interaction between virus propagation and honeynets (a simulated network composed of multiple honeypots; a honeypot is a security resource whose value lies in being scanned, attacked, and compromised. It deceives intruders by sacrificing a real, unpatched operating system to collect hacking attack methods and protect the real host target; honeynet technology is essentially a research-oriented, highly interactive honeypot technology. The difference between honeynets and traditional honeypot technologies is that honeynets constitute a hacker trapping network architecture, which can contain one or more honeypots, ensuring high network controllability and providing various tools for facilitating the collection and analysis of attack information.) and proposed a prevention strategy to limit virus propagation by improving honeynet design. Liu et al. analyzed the impact of cost and efficiency on different redundancy strategies and proposed a prevention strategy based on historical virus distribution. Bartas et al. proposed a network reputation database system to blacklist network entities with malicious behavior, achieving the effect of preventing virus intrusion. Wang et al. designed a mobile patching program to restore a network after virus infection based on the LDS "two-step" defense strategy. Qi et al. targeted the repair of virus-infected nodes in the network based on various network performance indicators. Li Wenguo, based on a distributed multi-agent self-healing control method, utilizes a self-healing recovery strategy to reduce the harm caused by virus propagation. Hu et al. proposed a real-time repair control strategy of "repairing while propagating," which can effectively control the spread of viruses in the network when the repair rate reaches a threshold.

[0008] Due to flaws in network security design, older industrial control equipment such as Programmable Logic Controllers (PLCs) prioritize reliability and effectiveness while neglecting security. This results in insecure network mechanisms, making them vulnerable to virus attacks. The multiple cross-couplings within industrial internet control systems facilitate virus spread and can cause cascading overload failures. Virus intrusions are often highly stealthy, potentially remaining dormant for extended periods. Traditional antivirus products, based on virus databases, have limitations in their application to industrial control systems. All these issues contribute to the industrial internet's vulnerability to virus attacks. While the industrial internet is rapidly integrating industrialization and informatization, it still faces new challenges in network security. If a virus infiltrates the industrial internet, it will inevitably cause significant damage to the entire network.

[0009] Therefore, studying the transmission patterns and prevention and control strategies of viruses can promptly sever the causal chain of virus transmission in the network, prevent the industrial internet from suffering significant losses due to virus infection, and help enhance the overall security and stability of the industrial internet.

[0010] The information disclosed in this background section is intended only to enhance the understanding of the general background of the invention and should not be construed as an admission or in any way implying that the information constitutes prior art known to those skilled in the art. Summary of the Invention

[0011] To address the shortcomings of existing technologies, the present invention aims to provide an industrial internet virus prevention and control method. This method constructs an industrial internet network model based on a network modeling approach, analyzes the model space and structural characteristics, assesses the importance of the industrial internet network model, analyzes the impact of relevant parameters on virus propagation, simulates the virus propagation process within the industrial control network, prevents further damage to the industrial internet caused by fault propagation, and facilitates timely post-incident network repair.

[0012] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0013] An industrial internet virus prevention and control method, the method being executable by one or more processors, comprising:

[0014] Step 1: The one or more processors construct a network topology model for the Industrial Internet;

[0015] Using industrial control system equipment in the Industrial Internet as nodes and information connection relationships between devices as edges, the Industrial Internet is abstracted into a network topology model based on the relationship between nodes and edges.

[0016] Step 2: The one or more processors evaluate the importance of nodes and classify the importance level of each node in the network;

[0017] The proximity C between the calculated nodes and the constructed positive and negative ideal solutions is used to determine the approximation. i To determine the importance of a node;

[0018] The proximity C of the ideal solution i The calculation formula is as follows:

[0019]

[0020] In the formula, D i + and D i - Let represent the distances from the index vector of node i to be evaluated to the positive and negative ideal solutions, respectively; N represents the total number of nodes i to be evaluated; and D represents the distance to the positive ideal solution.i + The smaller the value, the greater the distance D to the negative ideal solution. i - The larger the value, the closer the approximation C is to the ideal solution. i The larger it is, the bigger it becomes;

[0021] The calculated proximity is rounded to two decimal places to obtain the importance level, and the importance level of each node in the network is classified.

[0022] Step 3: The one or more processors establish a composite virus propagation model;

[0023] Step 4: The one or more processors analyze the composite virus propagation model;

[0024] In the industrial internet control system, the information management area and the production control area form a two-layer coupled network. Each PC and PLC device has internal links and external links. In the PC network, the internal links of the nodes are connected to the PCs and the external links are connected to the PLCs. In the PLC network, the internal links of the nodes are connected to the PLCs and the external links are connected to the PCs.

[0025] Each PC and PLC device has internal and external connectivity.

[0026] Based on the state transition diagram and state transition rate of the composite virus propagation model, a numerical analysis of the PC-PLC composite virus propagation model is performed. The changes in the number of nodes in the information management area network and the production control area network are obtained based on the differential equation of the model. The virus propagation situation is analyzed through two cases: disease-free balance and endemic balance. Under the composite virus propagation model, the state of all nodes can remain unchanged, so that the network reaches a stable state.

[0027] Step 5: The one or more processors construct virus propagation prevention and remediation control strategies.

[0028] Preferably, the specific steps for constructing the network topology model of the Industrial Internet are as follows: Abstract the devices within the industrial control system into a set of nodes V = {v1, v2, v3, ..., v...} in the network. n}, where n is the number of nodes; the information connection relationships between devices are abstracted into a set of edges in the network E = {e1, e2, e3, ..., e}. m}, where m is the number of edges, and e = for each edge.<u,v> Let e ​​represent the connecting edge between node u and node v; construct the network topology model of the Industrial Internet based on the relationship between nodes and edges.

[0029] Preferably, the specific steps for constructing the network topology model of the Industrial Internet also include: using formulas Calculate the clustering coefficient C of node x in the network topology model. x , where k x E represents the number of edges connecting node x to other nodes. x Indicates k x The number of actual edges between nodes; the clustering coefficient C is calculated if there are no neighboring nodes or only one neighboring node. x =0; based on formula C x Determine the clustering coefficient C of the entire network; based on the formula k x Calculate the average degree of the network in the network topology model. <k>Based on formula Calculate the node betweenness B in a network topology model. (z) , where g xy Let g be the sum of the number of shortest paths between nodes x and y. xy z(x) represents the number of shortest paths between nodes x and y that pass through node x; the average shortest path, the clustering coefficient C of the entire network, and the average degree are combined. <k>and node betweenness B (z) As model parameters, the model space and structural characteristics are analyzed through model parameters.

[0030] Preferably, when the importance is greater than or equal to 0.7, the importance level of the node is "high level"; when the importance is greater than or equal to 0.6 and less than 0.7, the importance level of the node is "relatively high level"; when the importance is greater than or equal to 0.55 and less than 0.6, the importance level of the node is "medium level"; and when the importance is less than 0.55, the importance level of the node is set to "low level".

[0031] Preferably, the specific steps for establishing a composite virus propagation model are as follows: Treating equipment infection caused by virus propagation as an external fault, and equipment overload induced by virus propagation as an internal fault, based on the SIR model, node states are defined to form a PC-PLC composite virus propagation model with ten states. Specifically: In the PC network, nodes are defined with susceptible, permanently immune, infected, immune, and isolated states; in the PLC network, nodes are defined with susceptible, permanently immune, infected, immune, and overload states; for overload faults induced by virus propagation, an overload state is set in the model, which refers to the maximum load state that the equipment in the industrial control system can handle; the capacity CO of node x... x Able to use the formula CO x =(1+a)L x Determined, among which, L x The initial load is given by α, and the constant α is the redundancy factor.

[0032] Preferably, the PC-PLC composite virus propagation model can be represented by the following set of 8 differential equations:

[0033] Solution of disease-free equilibrium in the PC-PLC composite virus transmission model It can be represented as:

[0034]

[0035] Solution of endemic disease equilibrium in the PC-PLC composite viral transmission model It can be represented as:

[0036]

[0037] 7. The industrial internet virus prevention and control method as described in claim 1, characterized in that, in step five, the prevention strategy reduces the probability of being attacked by viruses and improves the security and reliability of the network by adjusting the network structure, wherein the prevention strategy specifically includes: a prevention strategy based on expanding the connection surface, a prevention strategy based on enhancing the immunity level, and a prevention strategy based on increasing the load capacity.

[0038] The repair and control strategy reduces the impact of virus spread by isolating and / or repairing specific nodes after a virus attack occurs. Specifically, the repair and control strategy includes: a repair and control strategy based on isolation and immunity, and a repair and control strategy based on importance priority.

[0039] Preferably, the prevention strategy based on the extended connection surface includes: defining the number of connections between the PC network and the PLC network as the connection surface C. AB Based on formula C AB = <k> 12 ×N A Or C AB = <k> 21 ×N B Determine the connection surface C AB Based on the connecting surface C AB Adjust the network structure to reduce the probability of being attacked by viruses.

[0040] Preferably, the prevention strategy based on enhancing immune levels includes: constructing differential equations for immune state nodes in a virus transmission model: The immunity rates of infected and isolated nodes in PC networks and infected nodes in PLC networks are improved to enhance the immunity level; the prevention strategy based on increasing load capacity includes: constructing the differential equation of overloaded state nodes in the virus propagation model: Increase the overload rate of susceptible and infected nodes in the PLC network to improve load capacity.

[0041] Preferably, the isolation-immunity-based repair control strategy includes: when a virus invades the industrial control system, converting the PLC network to an immune state to effectively block virus transmission; when the virus spreads within the industrial control system, using isolation-immunity measures as a repair control strategy to ensure "isolation where necessary and repair where necessary," thereby inhibiting virus transmission and enhancing the security of the industrial internet; the importance-priority-based repair control strategy includes: when a virus begins to spread in the industrial control network, prioritizing the repair of nodes with higher importance to block the virus transmission path to the greatest extent; when repairing the industrial control system, prioritizing the repair of infected nodes with a "high" importance level.

[0042] The industrial internet virus prevention and control method described in this invention has the following innovations and beneficial effects compared with the prior art:

[0043] 1. In this invention, the importance of nodes is further classified through model parameters. Then, an industrial internet network model is constructed using a network model-based construction method. Model parameters (such as average shortest path, average clustering coefficient, average degree, and betweenness number) are used to analyze the model space and structural characteristics. The constructed network exhibits a degree of scale-free property and can classify nodes according to their importance, thus providing support for the precise suppression of industrial internet viruses. Compared to existing technologies that construct industrial internet network models based on network model construction methods, the network constructed in this invention can classify nodes according to their importance, thereby providing support for the precise suppression of industrial internet viruses.

[0044] 2. In this invention, a PC-PLC composite virus propagation model is established based on the load-capacity model and the SIR optimization model. The PC-PLC composite virus propagation model has ten states (SAIQR-SAIRF). Compared with existing technologies where virus propagation models are merely improvements on the load-capacity model or the SIR model, this invention uses a composite virus propagation model, which can more effectively simulate the propagation of viruses in the industrial internet.

[0045] 3. In this invention, an isolation state factor Q (Quarantine) is added to the PC network based on the SIR model, which can optimize the model. Compared with most existing SIR models that only consider infection and immunity status, this invention takes into account the isolation situation that may be involved in real-world scenarios, that is, intervening in infected devices to render them unable to spread, which requires model optimization.

[0046] 4. In this invention, a permanent immune status factor A (Antidotal) is added to both the PC network and the PLC network based on the SIR model, which can optimize the network. Compared with most existing SIR models that only consider temporary immune status, the SIR model of this invention adds a permanent immune status factor, which can optimize the state of the industrial control network.

[0047] 5. In this invention, a SIR optimization model is adopted in the PLC network. This model sets an overload state F (Fault) for overload faults induced by virus propagation, enabling all devices in the industrial control system to handle maximum load. Compared to existing technologies, the network constructed in this invention can effectively handle load and enhance the virus identification and tracking capabilities of the industrial control system.

[0048] 6. This invention proposes several prevention strategies for virus propagation applied to the Industrial Internet, including: prevention strategies based on extended connectivity, prevention strategies based on enhanced immunity, and prevention strategies based on increased load capacity. Compared to existing technologies, this invention combines multiple prevention strategies, making it more effective in preventing virus propagation in the Industrial Internet.

[0049] 7. This invention proposes several repair and control strategies for virus propagation applied to the Industrial Internet, including: a repair and control strategy based on isolation and immunity, and a repair and control strategy based on importance priority. Compared with the prior art, the repair strategies in this invention are more suitable for dealing with virus propagation in the Industrial Internet.

[0050] A series of numerical experiments were conducted to analyze the impact of the repair control strategy on virus transmission, verify the effectiveness of the repair control strategy, and improve the research on the virus transmission mechanism.

[0051] The expected effects of the prevention and control method described in this invention compared with traditional prevention and control methods are as follows:

[0052]

[0053] Attached Figure Description

[0054] The present invention includes the following figures:

[0055] The accompanying drawings are provided to better understand the invention and are not intended to unduly limit the scope of the invention. Wherein:

[0056] Figure 1 A flowchart of an embodiment of the industrial internet virus prevention and control method described in this invention.

[0057] Figure 2 Network topology model of an industrial internet control system.

[0058] Figure 3 Importance of nodes in an industrial internet control system.

[0059] Figure 4 Importance classification of a certain industrial internet control system.

[0060] Figure 5 State transition diagram of PC-PLC composite virus propagation model with conversion rate.

[0061] Figure 6 Changes in the number of infected nodes under different connection planes in a PC network.

[0062] Figure 7 Changes in the number of infected nodes under different connection surfaces in the PLC network.

[0063] Figure 8 Changes in the number of infected nodes under different immunization rates in PC networks.

[0064] Figure 9 Changes in the number of infected nodes under different immunization rates in the PLC network.

[0065] Figure 10 Changes in the number of overloaded nodes under different susceptibility overload rates in a PLC network.

[0066] Figure 11 Changes in the number of overloaded nodes under different infection overload rates in a PLC network.

[0067] Figure 12 Changes in the number of infected nodes in the two models in the PC network.

[0068] Figure 13 Changes in the number of infected nodes in the two models of the PLC network.

[0069] Figure 14 Changes in the number of infected nodes under different repair rates in PC networks.

[0070] Figure 15 Changes in the number of infected nodes under different repair rates in the PLC network.

[0071] Figure 16 Changes in the number of infected nodes under different repair methods in PC networks.

[0072] Figure 17 Changes in the number of infected nodes under different repair methods in the PLC network.

[0073] The specific meanings of the symbols used are shown in the table below:

[0074]

[0075] Detailed Implementation

[0076] The present invention will be further described in detail below with reference to the accompanying drawings. This detailed description is an illustration in conjunction with exemplary embodiments of the invention, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0077] This invention proposes a method for preventing and controlling viruses in the industrial internet, such as... Figure 1 As shown, the specific steps of this method are as follows:

[0078] Step 1: Construct a network topology model for the Industrial Internet;

[0079] Using industrial control system equipment in the Industrial Internet as nodes and information connection relationships between devices as edges, the Industrial Internet is abstracted into a network topology model based on the relationship between nodes and edges.

[0080] Step 2: Assess node importance and classify the importance level of each node in the network;

[0081] The proximity C between the calculated nodes and the constructed positive and negative ideal solutions is used to determine the approximation. i To determine the importance of a node;

[0082] The proximity C of the ideal solution i The calculation formula is as follows:

[0083]

[0084] In the formula, D i + and D i - Let represent the distances from the index vector of node i to be evaluated to the positive and negative ideal solutions, respectively; N represents the total number of nodes i to be evaluated; and D represents the distance to the positive ideal solution. i + The smaller the value, the greater the distance D to the negative ideal solution. i - The larger the value, the closer the approximation C is to the ideal solution. i The larger it is, the bigger it becomes;

[0085] The calculated proximity is rounded to two decimal places to obtain the importance score, which is then used to classify the importance level of each node in the network; for example:

[0086] For nodes with an importance score of 0.75 or higher, the importance level is set to "high level".

[0087] For nodes with an importance score greater than or equal to 0.6 and less than 0.75, the importance level is set to "higher level";

[0088] For nodes with an importance score greater than or equal to 0.5 and less than 0.6, the importance level is set to "medium level".

[0089] For nodes with an importance score less than 0.5, set their importance level to "low level".

[0090] Step 3: Establish a composite virus transmission model;

[0091] Device infection caused by virus propagation is considered an external failure, and device overload induced by virus propagation is considered an internal failure. Based on the SIR model, node states are defined, where:

[0092] In the PC network of the information management area, nodes are defined to have four states: S represents Susceptible, I represents Infection, Q represents Quarantine, and R represents Recovery.

[0093] In the PLC network of the production control area, nodes are defined to have four SIRF states: S represents Susceptible, I represents Infection, R represents Recovery, and F represents Fault.

[0094] Establish a PC-PLC composite virus propagation model for the Industrial Internet, with nodes having ten states from SAIQR to SAIRF;

[0095] Step 4: Analysis of the composite virus transmission model;

[0096] In an industrial internet control system, the information management area is mainly composed of PCs, forming a PC network; the production control area is mainly composed of PLCs, forming a PLC network. The two areas form a two-layer coupled network, with PC networking above and PLC networking below. That is, each PC and PLC device has internal and external links. In the PC network, the internal links of nodes are connected to PCs, and the external links are connected to PLCs. Similarly, in the PLC network, the internal links of nodes are connected to PLCs, and the external links are connected to PCs.

[0097] Each PC and PLC device has two levels of connectivity: internal connectivity and external connectivity.

[0098] When a PLC device is infected with a virus, it can spread not only within the PLC network (through internal links) but also within the PC network (through external links); similarly, when a PC device is infected with a virus, it can spread not only within the PC network but also within the PLC network. This situation is called the virus propagation between the two networks, or the coupling effect between networks.

[0099] In PC networks, the main research focuses on virus infection caused by virus propagation; in PLC networks, the main research focuses on virus infection caused by virus propagation and overload failures induced by virus infection.

[0100] Based on the state transition diagram and state transition rate of the composite virus propagation model, a numerical analysis of the PC-PLC composite virus propagation model is conducted. The changes in the number of nodes in the information management area network and the production control area network are obtained based on the differential equation of the model. The virus propagation situation is analyzed through two cases: disease-free equilibrium and endemic equilibrium. Under the composite virus propagation model, the PC-PLC network can reach an equilibrium point, that is, the state of all nodes no longer changes, and the network reaches a stable state.

[0101] Step 5: Develop prevention and control strategies for virus transmission;

[0102] The aforementioned prevention strategy reduces the probability of being attacked by viruses and improves network security and reliability by adjusting the network structure.

[0103] The prevention strategies specifically include: prevention strategies based on extended connectivity, prevention strategies based on enhanced immunity, and prevention strategies based on increased load capacity.

[0104] The repair and control strategy reduces the impact of virus spread by isolating and / or repairing specific nodes after a virus attack occurs.

[0105] The repair control strategies specifically include: a repair control strategy based on isolation and immunity, and a repair control strategy based on importance priority.

[0106] Through the above steps, the propagation process of industrial internet viruses is suppressed, the problem of fault propagation within the network node is solved, and it is applicable to controlling the status of equipment within the industrial internet to prevent large-scale failures, reduce the scope of fault propagation, and minimize economic losses when a fault occurs.

[0107] Based on the above technical solution, the specific steps of step one are as follows:

[0108] First, the devices within the industrial control system are abstracted into a set of nodes V in a network.

[0109] V = {v1, v2, v3, ..., v} n },

[0110] In the formula, n is the number of nodes, that is, there are a total of n nodes;

[0111] Then, the information connection relationships between devices are abstracted into a set E of edges in the network.

[0112] E = {e1, e2, e3, ..., e} m },

[0113] In the formula, m is the number of edges, that is, there are a total of m edges;

[0114] Each edge e =<u,v> , indicating that e is the connecting edge between node u and node v;

[0115] Construct a network topology model for the Industrial Internet based on the relationships between nodes and edges.

[0116] This invention uses graph theory to describe the topology of complex systems. In the Industrial Internet, devices within an industrial control system are abstracted as nodes, and the information connection relationships between devices are abstracted as edges. Figure 2 The image shows a network topology model for an industrial internet.

[0117] Based on the above technical solution, the specific steps of step one also include:

[0118] Calculate the clustering coefficient C of node x in the network topology model. x The formula is:

[0119]

[0120] In the formula, k x E represents the number of edges connecting node x to other nodes. x Then it means k x The actual number of edges between nodes;

[0121] If a node has no neighboring nodes (degree 0) or only one neighboring node (degree 1), its clustering coefficient C is... x =0;

[0122] The average of the clustering coefficients of all nodes gives the clustering coefficient C of the entire network, calculated using the following formula:

[0123]

[0124] Calculate the average degree of the network in the network topology model. <k>The formula is:

[0125]

[0126] Calculate the node betweenness B in a network topology model. (z) The formula is:

[0127]

[0128] In the formula, g xy Let g be the sum of the number of shortest paths between nodes x and y. xy z(x) is the number of shortest paths between nodes x and y that pass through node x; for example Figure 3 As shown;

[0129] The average shortest path, the clustering coefficient C of the entire network, and the average degree are used to calculate the average shortest path, the clustering coefficient C of the entire network, and the average degree. <k>and node betweenness B (z) As model parameters, the model space and structural characteristics are analyzed through model parameters.

[0130] The constructed network lacks small-world properties and has a certain degree of scale-freeness.

[0131] Based on the above technical solution, in step two, nodes with an importance score greater than or equal to 0.7 are assigned an importance level of "high level"; nodes with an importance score greater than or equal to 0.6 and less than 0.7 are assigned an importance level of "relatively high level"; nodes with an importance score greater than or equal to 0.55 and less than 0.6 are assigned an importance level of "medium level"; and nodes with an importance score less than 0.55 are assigned an importance level of "low level". Figure 4 As shown.

[0132] Based on the above technical solution, the specific steps of step three are as follows:

[0133] In PC networks, nodes are defined to have five states: SAIQR. S state stands for Susceptible, A state stands for Antidotal, I state stands for Infection, R state stands for Recovery, and Q state stands for Quarantine.

[0134] In a PLC network, nodes are also defined with five states: S (Susceptible), A (Antidotal), I (Infection), R (Recovery), and F (Fault). This forms a PC-PLC composite virus propagation model with ten states (SAIQR-SAIRF), as detailed below. Figure 5 As shown.

[0135] For overload faults induced by virus transmission, an overload state is set in the model. The overload state refers to the maximum load state that the equipment in the industrial control system can handle.

[0136] The capacity CO of node x x It is proportional to the initial load of the node:

[0137] CO x =(1+a)L x

[0138] In the formula, L x The initial load is given by a constant a, which is a redundancy coefficient. Its non-negativity a > 0 ensures that all nodes in the network are in a working state at the initial moment.

[0139] Based on the above technical solution, the specific steps of step four are as follows:

[0140] Based on the established transformation relationship, the PC-PLC composite virus propagation model can be expressed as a system of 8 differential equations;

[0141]

[0142] Each of the above equations is a derivative, representing the rate of change of a node under a specific state;

[0143] Disease-free equilibrium is equivalent to setting all equations in the formula to zero, indicating that no further state changes occur, resulting in the formula, and since there are no infected nodes, i.e. If this holds true, the solution for the model's disease-free equilibrium can be obtained.

[0144]

[0145] The conditions for endemic disease balance to be satisfied are as follows: no more state changes occur, and the transition rate of all states is zero; there are some infected nodes in the PC-PLC network.

[0146] In the model, endemic equilibrium is equivalent to setting all equations to zero to indicate that no further state changes occur. However, due to the existence of infection nodes, i.e. Established;

[0147] Endemic disease balance, denoted as

[0148]

[0149] Based on the above technical solutions, in step five, the prevention strategy mainly considers reducing the probability of being attacked by viruses and improving the security and reliability of the network by adjusting the network structure; while the repair and control strategy mainly considers how to reduce the impact of virus spread by isolating and repairing specific nodes after a virus attack occurs.

[0150] This paper proposes prevention strategies based on expanding connectivity, enhancing immune levels, and increasing load capacity. It also proposes repair control strategies based on isolation immunity and priority-based repair control strategies.

[0151] The prevention strategy based on the extended connection surface includes:

[0152] The number of connections between the PC and PLC network is defined as connection surface C. AB ,according to <k> mn The definition allows us to calculate the connection surface C. AB See the formula;

[0153] C AB = <k> 12 ×N A Or C AB = <k> 21 ×N B ;

[0154] To study the expansion of the PC-PLC connection surface C AB The effectiveness of prevention strategies is assessed by gradually increasing the average degree. <k> 12 and <k> 21 and keep <k> 11 and <k> 22 Unchanged; with average degree <k> 12 and <k> 21 As the number of infected nodes increases (from 4 to 8), the number of infected nodes first increases and then decreases, eventually reaching a stable state; connection surface C AB As the network size increases, the peak number of infected nodes in PLC and PC networks decreases; in industrial internet scenarios, due to business needs, PCs and PLCs need to be connected, and as the connection surface expands, the number of infected nodes will eventually decrease; for example... Figure 6 , 7 As shown; further define P A (i, j), P B (k, l) represents the joint degree distribution in the PC network (Network A) and the PLC network (Network B), P A (i,·), P A (·,j), P B (k,·), P B (·, l) represents the marginal degree distribution, the joint degree fraction, and the marginal degree distribution:

[0155]

[0156]

[0157]

[0158] Define average degree <k>and the second moment of degree <k 2 >:

[0159]

[0160]

[0161]

[0162]

[0163] The prevention strategies based on enhancing immune levels include:

[0164] According to the differential equation of the immune status node in the virus transmission model, the enhancement of the immune level depends in part on the improvement of the immune rate of infected nodes and isolated nodes in the PC network and the immune rate of infected nodes in the PLC network.

[0165]

[0166]

[0167] In industrial internet scenarios, the immunity of industrial control systems can be enhanced by upgrading firmware and optimizing security protocols; as immunity increases, the number of infections will eventually decrease; for example... Figure 8 , 9 As shown;

[0168] The prevention strategy based on increasing load capacity includes:

[0169] The capacity CO of node x x It is proportional to the initial load of the node:

[0170] CO x =(1+a)L x

[0171] In the formula, L x The initial load is defined by a constant 'a', which is a redundancy coefficient. The non-negativity of 'a > 0' ensures that all nodes in the network are initially operational. As the virus spreads, the capacity CO of node x decreases. x The value will gradually increase, and when the load exceeds the capacity, an overload failure will occur; there is a certain non-linear relationship between the redundancy coefficient and the overload rate of nodes in the virus propagation model. The smaller the redundancy coefficient, the smaller the overload rate of the industrial control system equipment; therefore, increasing the load capacity in the industrial control system is equivalent to reducing the redundancy coefficient, thereby suppressing overload failures of equipment in the industrial control system.

[0172] The differential equation for the overload state node in the virus propagation model is:

[0173]

[0174] As can be seen from the formula, the number of overloaded nodes partly depends on the overload rate of susceptible and infected nodes in the PLC network; for example... Figure 10 , 11 As shown;

[0175] The isolation-based immune repair control strategy includes:

[0176] When a virus infiltrates an industrial control system, the isolation and immunization repair control strategy adopted to block virus transmission faces a significant challenge in its effectiveness. To study the control effect of the repair control strategy, numerical experiments were conducted by gradually increasing the repair rate of infected nodes, comparing the number of infections under different repair rates. Although it is impossible to repair the PLC by isolating it, the PLC can be converted to an immune state through methods such as antivirus patch repair, which can still effectively block virus transmission. Figure 12 , 13 As shown;

[0177] In the Industrial Internet, industrial control systems can be repaired by installing isolation patches and antivirus software. As repair capabilities improve, virus propagation is gradually brought under control. Therefore, when viruses spread within industrial control systems, isolation and immunization measures can be used as a repair control strategy, ensuring "isolation where necessary and repair where necessary," thereby inhibiting virus spread and enhancing the security of the Industrial Internet. Figure 14 , 15 As shown, isolation and immunization measures are an effective way to control the spread of viruses. By modifying the node state to an isolated or immunized state, diseased nodes can be isolated, thereby achieving repair and control of the internal working system. In the power industry internet, the working system can be repaired by installing isolation patches, antivirus software, and other means. With the improvement of repair capabilities, the spread of viruses has gradually been effectively controlled.

[0178] The importance-based repair control strategy includes:

[0179] In the industrial internet scenario, important nodes can make the network structure and functionality more stable. If a relatively important node is infected with a virus, it will inevitably cause more serious spread and more serious consequences. Therefore, when a virus begins to spread in the industrial control network, prioritizing the repair of some high-importance nodes can block the spread of the virus to the greatest extent and control its spread.

[0180] When repairing industrial control systems, priority is given to repairing infected nodes with a "high" importance level. A high repair rate is not required to effectively control virus spread. This importance-priority-based repair control strategy improves repair efficiency, maximizes repair effectiveness, and enhances the security of the industrial internet. Figure 16 , 17 As shown.

[0181] The contents not described in detail in this specification are existing technologies known to those skilled in the art.

[0182] The above description is only a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. Any equivalent modifications or changes made by those skilled in the art based on the content disclosed in the present invention should be included in the scope of protection set forth in the claims.< / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k> < / k>

Claims

1. A method for preventing and controlling viruses in the industrial internet, characterized in that, The method can be executed by one or more processors, including: Step 1: The one or more processors construct a network topology model for the Industrial Internet; Using industrial control system equipment in the Industrial Internet as nodes and information connection relationships between devices as edges, the Industrial Internet is abstracted into a network topology model based on the relationship between nodes and edges. Step 2: The one or more processors evaluate the importance of nodes and classify the importance level of each node in the network; The proximity C between the calculated nodes and the constructed positive and negative ideal solutions is used to determine the approximation. i To determine the importance of a node; The proximity C of the ideal solution i The calculation formula is as follows: ; In the formula, D i + and D i - Let represent the distances from the index vector of node i to be evaluated to the positive and negative ideal solutions, respectively; N represents the total number of nodes i to be evaluated; and D represents the distance to the positive ideal solution. i + The smaller the value, the greater the distance D to the negative ideal solution. i - The larger the value, the closer the approximation C is to the ideal solution. i The larger it is, the bigger it becomes; The calculated proximity is rounded to two decimal places to obtain the importance level, and the importance level of each node in the network is classified. Step 3: The one or more processors establish a composite virus propagation model; Step 4: The one or more processors analyze the composite virus propagation model; In the industrial internet control system, the information management area and the production control area form a two-layer coupled network. Each PC and PLC device has internal links and external links. In the PC network, the internal links of the nodes are connected to the PCs and the external links are connected to the PLCs. In the PLC network, the internal links of the nodes are connected to the PLCs and the external links are connected to the PCs. Each PC and PLC device has internal and external connectivity. Based on the state transition diagram and state transition rate of the composite virus propagation model, a numerical analysis of the PC-PLC composite virus propagation model is performed. The changes in the number of nodes in the information management area network and the production control area network are obtained based on the differential equation of the model. The virus propagation situation is analyzed through two cases: disease-free balance and endemic balance. Under the composite virus propagation model, the state of all nodes can remain unchanged, so that the network reaches a stable state. Step 5: The one or more processors construct virus propagation prevention and remediation control strategies.

2. The industrial internet virus prevention and control method as described in claim 1, characterized in that, The specific steps for constructing a network topology model for the Industrial Internet are as follows: Abstracting the devices within an industrial control system into a set of nodes in a network. , where n is the number of nodes; The information connections between devices are abstracted into a set of edges in the network. Where m is the number of edges, and each edge , indicating that e is the connecting edge between node u and node v; Construct a network topology model for the Industrial Internet based on the relationships between nodes and edges.

3. The industrial internet virus prevention and control method as described in claim 2, characterized in that, The specific steps for constructing a network topology model for the Industrial Internet also include: Through formula Calculate the clustering coefficient C of node x in the network topology model. x , where k x E represents the number of edges connecting node x to other nodes. x Indicates k x The actual number of edges between nodes; If a node has no neighbor nodes or only one neighbor node, its clustering coefficient C is... x =0; Based on formula Determine the clustering coefficient C for the entire network; Based on formula Calculate the average degree of the network in the network topology model. <k> ;< / k> Based on formula Calculate the node betweenness B in a network topology model. (z) ,in, This represents the total number of shortest paths between nodes x and y. The average shortest path, the clustering coefficient C of the entire network, and the average degree are used to calculate the average shortest path, the average clustering coefficient C of the entire network, and the average degree. <k>and node betweenness B (z) As model parameters, the model space and structural characteristics are analyzed through model parameters.< / k> 4. The industrial internet virus prevention and control method as described in claim 1, characterized in that, When the importance score is greater than or equal to 0.7, the node's importance level is "high level"; when the importance score is greater than or equal to 0.6 and less than 0.7, the node's importance level is "relatively high level"; when the importance score is greater than or equal to 0.55 and less than 0.6, the node's importance level is "medium level"; when the importance score is less than 0.55, the node's importance level is set to "low level".

5. The industrial internet virus prevention and control method as described in claim 1, characterized in that, The specific steps for establishing a composite virus transmission model are as follows: The virus infection of equipment caused by virus propagation is considered an external failure, and the equipment overload induced by virus propagation is considered an internal failure. Based on the SIR model, node states are defined to form a PC-PLC composite virus propagation model with ten states, where: In a PC network, nodes are defined to have susceptible, permanently immune, infected, immune, and isolated states. In a PLC network, nodes are defined to have susceptible, permanently immune, infected, immune, and overload states. For overload faults induced by virus transmission, an overload state is set in the model. The overload state refers to the maximum load state that the equipment in the industrial control system can handle. The capacity CO of node x x Able to use formula Determined, among which, L x The initial load is given by α, and the constant α is the redundancy factor.

6. The industrial internet virus prevention and control method as described in claim 5, characterized in that, The PC-PLC composite virus propagation model can be represented by the following set of 8 differential equations: ; Solution of disease-free equilibrium in the PC-PLC composite virus transmission model It can be represented as: ; Solution of endemic disease equilibrium in the PC-PLC composite viral transmission model It can be represented as: ; In the formula: The number of nodes in a PC network; The number of nodes in the PLC network; PC network moderate The number of nodes; : PLC network is moderate The number of nodes; The degree at time t is The number of susceptible PC nodes; The degree at time t is The number of infected PC nodes; The degree at time t is The number of isolated PC nodes; The degree at time t is The number of immune PC nodes; The degree at time t is The number of susceptible PLC nodes; The degree at time t is The number of infected PLC nodes; The degree at time t is The number of immune PLC nodes; The degree at time t is The number of overloaded PLC nodes; Infection rate of susceptible PC nodes connecting to infected PC nodes; Infection rate of susceptible PC nodes connected to infected PLC nodes; Infection rate of susceptible PLC nodes connected to infected PC nodes; Infection rate of susceptible PLC nodes connected to infected PLC nodes; : Immunization rate of infected PC nodes; : Immunization rate of infected PLC nodes; Susceptibility rate of immune PC nodes; Susceptibility rate of immune PLC nodes; : Isolation rate of infected PC nodes; : Immunity rate of isolated PC nodes; Overload rate of susceptible PLC nodes; Overload rate of infected PLC nodes; Birth and death rates at PC nodes; Birth and death rates of PLC nodes; Susceptibility rate of newly formed PC nodes; : Immunity rate of newly formed PC nodes.

7. The industrial internet virus prevention and control method as described in claim 6, characterized in that, In step five, the prevention strategy reduces the probability of being attacked by viruses and improves the security and reliability of the network by adjusting the network structure. Specifically, the prevention strategy includes: a prevention strategy based on expanding the connection surface, a prevention strategy based on enhancing the immunity level, and a prevention strategy based on increasing the load capacity. The repair and control strategy reduces the impact of virus spread by isolating and / or repairing specific nodes after a virus attack occurs. Specifically, the repair and control strategy includes: a repair and control strategy based on isolation and immunity, and a repair and control strategy based on importance priority.

8. The industrial internet virus prevention and control method as described in claim 7, characterized in that, The prevention strategy based on the extended connection surface includes: The number of connections between the PC network and the PLC network is defined as the connection surface. Based on the formula or Determine the connection surface ; In the formula: This represents the average degree of the network in the network topology model; subscript 1 means 1 edge; subscript 2 means 2 nodes; This represents the average degree of the network in the network topology model; subscript 2 means 2 edges; subscript 1 means 1 node. Based on the connection surface Adjust the network structure to reduce the probability of being attacked by viruses.

9. The industrial internet virus prevention and control method as described in claim 7, characterized in that, The prevention strategies based on enhancing immune levels include: Construct the differential equations for the immune state nodes in the virus transmission model: ; ; To enhance immunity, the immunity rates of infected and isolated nodes in PC networks and infected nodes in PLC networks are increased. The prevention strategy based on increasing load capacity includes: Construct the differential equations for the overloaded state nodes in the virus propagation model: ; Increase the overload rate of susceptible and infected nodes in the PLC network to improve load capacity.

10. The industrial internet virus prevention and control method as described in claim 7, characterized in that, The isolation-based immune repair control strategy includes: When a virus infiltrates an industrial control system, the PLC network is switched to an immune state to effectively block the spread of the virus. When a virus spreads within an industrial control system, isolation and immunization measures are used as a repair and control strategy to ensure that "all viruses that need to be isolated are isolated and all viruses that need to be repaired are repaired," thereby inhibiting the spread of the virus and enhancing the security of the industrial internet. The importance-based repair control strategy includes: Once the virus begins to spread in the industrial control network, prioritize repairing the nodes with higher importance in order to block the spread of the virus to the greatest extent possible. When repairing industrial control systems, prioritize repairing infected nodes with an importance level of "high".

Citation Information

Patent Citations

  • Network virus transmission behavior modeling method

    CN105357200A

  • Method for constructing network virus diffusion model based on epidemic dynamics

    CN108322328A