A method for industrial control system vulnerability assessment

By constructing a minimum inspection unit and configuring evaluation and statistical functions, and adjusting weight parameters in conjunction with historical data, a linear three-layer perceptron model is used to assess the vulnerability of industrial control systems. This addresses the shortcomings of existing assessment methods and achieves highly accurate and robust assessment results.

CN116430823BActive Publication Date: 2025-11-25XIAN THERMAL POWER RES INST CO LTD +1

Patent Information

Application Number
CN202310087731.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-12-14
Filing Date
2023-02-03
Publication Date
2025-11-25
Estimated Expiration
2043-02-03

AI Technical Summary

Technical Problem

The lack of effective methods in the current technology to assess the vulnerability of industrial control systems makes them very vulnerable to cyberattacks.

Method used

The minimum inspection unit is constructed and the evaluation and statistical functions are configured. Based on historical data, the weight parameters are adjusted through linear regression and normal distribution function, and the evaluation is carried out using a linear three-layer perceptron model to avoid error amplification.

Benefits of technology

This improves the accuracy and robustness of vulnerability assessments for industrial control systems, reduces error propagation, and ensures the reliability of assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116430823B_ABST
    Figure CN116430823B_ABST
Patent Text Reader

Abstract

The application discloses a kind of industrial control system vulnerability evaluation methods, comprising: constructing several minimum check units for industrial control system vulnerability evaluation, each minimum check unit is configured evaluation function and the core check item of industrial control system, and the statistical function and weight parameter are configured for each core check item;Each minimum check unit is executed, and the check result of minimum check unit is evaluated by evaluation function, and the evaluation score corresponding to each minimum check unit is obtained;According to the statistical function corresponding to each core check item, the evaluation score of corresponding minimum check unit is processed, and the statistical score of each core check item is obtained, and the vulnerability score is calculated according to the statistical score of each core check item and weight parameter, and then the vulnerability of industrial control system is evaluated according to the vulnerability score, which can evaluate the vulnerability of industrial control system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of industrial control security technology and relates to a method for assessing the vulnerability of industrial control systems. Background Technology

[0002] Industrial control systems are a crucial component of national critical infrastructure, widely used in industries such as petroleum and petrochemicals, water conservancy, power, food processing, and wastewater treatment, primarily for data acquisition and production control. With the widespread application of computer technology in industrial environments, general-purpose computing devices and operating systems are increasingly used in industrial control systems, and protocols are being built based on TCP / IP. Traditional industrial control systems are gradually breaking down their previous closed and proprietary nature, allowing threats faced by traditional internet systems to spread to the industrial control system environment. Simultaneously, due to system compatibility issues, industrial control systems are typically not upgraded or patched, leading to the accumulation of numerous security vulnerabilities over long periods of operation. These deficiencies make industrial control systems highly vulnerable to cyberattacks, yet current technologies lack methods for assessing the vulnerabilities of industrial control systems. Summary of the Invention

[0003] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method for assessing the vulnerability of industrial control systems.

[0004] To achieve the above objectives, the present invention adopts the following technical solution:

[0005] The vulnerability assessment method for industrial control systems described in this invention includes:

[0006] Construct several minimum inspection units for vulnerability assessment of industrial control systems, configure evaluation functions and core inspection items of the industrial control system for each minimum inspection unit, and configure statistical functions and weight parameters for each core inspection item.

[0007] Each minimum inspection unit is executed, and the inspection results of each minimum inspection unit are evaluated using an evaluation function to obtain an evaluation score for each minimum inspection unit.

[0008] Based on the statistical function corresponding to each core inspection item, the evaluation score of the corresponding smallest inspection unit is processed to obtain the statistical score of each core inspection item. Based on the statistical score of each core inspection item and the weight parameter, the vulnerability score is calculated, and then the vulnerability of the industrial control system is assessed based on the vulnerability score.

[0009] It also includes: configuring a self-test function for each minimum inspection unit; processing the inspection results of each minimum inspection unit according to the self-test function and evaluation function corresponding to each minimum inspection unit to obtain the current evaluation score and environmental variables; calculating the corresponding normal distribution function based on the evaluation scores of the same environmental variables in the historical records of the minimum inspection unit; and determining whether the current evaluation score satisfies the normal distribution function; if not, updating the weight parameters of the statistical function.

[0010] Based on the historical evaluation scores of the smallest inspection unit and environmental variables, a linear regression equation between the evaluation scores and environmental variables is calculated, and the current evaluation score is predicted using the linear regression equation.

[0011] The linear regression equation uses the sum of squared errors to represent the loss function.

[0012] The weight parameters of the statistical function are updated based on the error between the actual evaluation score and the current evaluation score.

[0013] The normal distribution function is:

[0014]

[0015] Where μ is the expected value of the historical evaluation score, σ 2 Let x be the variance of the historical evaluation scores.

[0016] Determine whether the deviation between the expected historical evaluation score and the current evaluation score exceeds a preset range; if it does, then the normal distribution function is not satisfied.

[0017] The present invention has the following beneficial effects:

[0018] In practical operation, the industrial control system vulnerability assessment method described in this invention sets up several minimum inspection units for industrial control system vulnerability assessment, configures a corresponding evaluation function for each minimum inspection unit, and constructs at least two core inspection items using the set minimum inspection units, configuring a corresponding statistical function and weight parameters for each core inspection item. By executing all minimum inspection units and corresponding core inspection items, and combining the historical data of the minimum inspection units, it is determined whether the error conforms to a normal distribution, and then the weight parameters of the statistical function are adjusted to avoid amplifying the error when it propagates from deep to surface, thereby making the final assessment result as accurate as possible. Attached Figure Description

[0019] The accompanying drawings, which form part of this specification, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings:

[0020] Figure 1 This is a schematic diagram of the process of the present invention;

[0021] Figure 2 This is a schematic diagram of the node network structure of a three-layer perceptron. Detailed Implementation

[0022] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0024] The present invention will now be described in further detail with reference to the accompanying drawings:

[0025] refer to Figure 1 and Figure 2 The vulnerability assessment method for industrial control systems described in this invention includes the following steps:

[0026] Several minimum inspection units are set up for vulnerability assessment of industrial control systems, and corresponding evaluation functions and self-test functions are configured for each minimum inspection unit. Several core inspection items are constructed using the set minimum inspection units, and corresponding statistical functions and evaluation weights are configured for each core inspection item.

[0027] Each minimum check unit is executed, and the check results are processed according to the evaluation function and self-check function corresponding to each minimum check unit to obtain the current evaluation score and environmental variables respectively. Moreover, based on the evaluation scores of the minimum check unit under the same environmental variables in the historical records, the corresponding normal distribution function is calculated, and it is determined whether the current evaluation score satisfies the normal distribution function. If it does, the execution continues; otherwise, the weight parameters of the statistical function are updated.

[0028] Based on the statistical function corresponding to each core inspection item, the evaluation score of its smallest inspection unit is processed to obtain the statistical score corresponding to each core inspection item; based on the statistical score and evaluation weight of each core inspection item, the vulnerability score is calculated; wherein, the higher the vulnerability score, the higher the vulnerability strength.

[0029] In this invention, the smallest inspection unit is a functional module subdivided into many smallest states that can be evaluated, possessing atomicity and independence. For example, in vulnerability scanning, the smallest evaluation unit is to independently evaluate the details of a single vulnerability detected during scanning.

[0030] This invention takes into account that simple linear models without feedback mechanisms will amplify errors, while overly complex network models place high demands on the system's computational power and time. Therefore, this invention configures a corresponding self-test function for each smallest inspection unit and generates an environment variable obtained from the self-test function when the evaluation score is used as the input for the core inspection item.

[0031] Suppose the system runs 100 times, generating 100 evaluation scores and environmental variable records. During idle time, the system calculates the linear regression equation between the input and environmental variables for each inspection unit, and uses the sum of squared errors to represent the loss function. Errors are influenced by many factors and can be considered as the sum of these factors (random variables). Therefore, the error between the actual and predicted values ​​follows a normal distribution. When an input that does not conform to this distribution is found, the system performs a self-check by comparing it with its environmental variables. If a system configuration problem is found, it is fed back to the system presentation layer; if it is a parameter problem, the system self-adjusts the weights based on the simulated error magnitude. Generally, the larger the error, the greater the decrease in the corresponding weight coefficient.

[0032] Specifically, the normal distribution function is:

[0033]

[0034] Where μ is the expected value of the historical evaluation score, σ 2 Let x be the variance of the historical evaluation scores, and x be the evaluation score.

[0035] The method for determining whether the current evaluation score satisfies the normal distribution function is as follows: determine whether the deviation between the expected evaluation score of the current historical record and the current evaluation score exceeds a preset range; if it exceeds, then the normal distribution function is not satisfied.

[0036] In the industrial control system vulnerability assessment method of the present invention, each inspection unit is equipped with a memory analysis system or a periodic self-looping system for its input. This ensures that the system vulnerability score will not fluctuate due to a single human configuration or system parameter error over a long period of time. Moreover, the error range can be guaranteed from the lowest level, increasing the robustness of the system assessment model.

[0037] Furthermore, due to the complexity and suddenness of the system, each smallest inspection unit is at the lowest level, and each error adjustment requires the accumulation of a certain number of samples. Therefore, the timeliness of system adjustment is insufficient, and complementary intervention configuration schemes need to be designed.

[0038] Specifically, each core inspection item is also configured with a corresponding bias. The general design is to evaluate the weight result through w, i.e., y = x * w; by adding the bias b, the final result becomes y = x * w + b, which can effectively incorporate human decision-making and make the error optimized through the complementary combination of system and human intervention.

[0039] like Figure 2 As shown, the industrial control system vulnerability assessment method of the present invention draws on the working principle of a linear three-layer perceptron. It sets multiple minimum inspection units for industrial control system vulnerability assessment, configures a corresponding evaluation function and self-test function for each minimum inspection unit, and constructs at least two core inspection items using the set minimum inspection units, configuring a corresponding statistical function and evaluation weight for each core inspection item. By executing all minimum inspection units and their corresponding core inspection items, and combining the historical data of the minimum inspection units, it determines whether the error conforms to a normal distribution, and then adjusts the weight parameters of the statistical function. Therefore, the present invention can avoid the amplification of errors when they propagate forward from deep to surface, thereby making the final assessment result as accurate as possible.

[0040] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A vulnerability assessment method for industrial control systems, characterized in that, include: Construct several minimum inspection units for vulnerability assessment of industrial control systems, configure evaluation functions and core inspection items of the industrial control system for each minimum inspection unit, and configure statistical functions and weight parameters for each core inspection item. At least two core inspection items are constructed using the set minimum inspection units. The minimum inspection unit is a functional module that is subdivided into multiple minimum states that can be evaluated. Each minimum check unit is executed, and the execution result of the minimum check unit is evaluated using an evaluation function to obtain the evaluation score corresponding to each minimum check unit. Based on the statistical function corresponding to each core inspection item, the evaluation score of the smallest inspection unit corresponding to each core inspection item is processed using the statistical function to obtain the statistical score of each core inspection item. Based on the statistical score of each core inspection item and the weight parameter, the vulnerability score is calculated, and then the vulnerability of the industrial control system is assessed based on the vulnerability score. It also includes: configuring a self-checking function for each minimum check unit; processing the execution results of the minimum check unit using the self-checking function and evaluation function corresponding to each minimum check unit to obtain the current evaluation score and environmental variables of the minimum check unit; calculating the corresponding normal distribution function based on the evaluation scores of the same environmental variables in the historical records of the minimum check unit; and determining whether the current evaluation score satisfies the normal distribution function; if not, updating the weight parameters of the statistical function. Based on the historical evaluation scores and environmental variables of the smallest inspection unit, a linear regression equation between the evaluation scores and environmental variables is calculated, and the current evaluation score is predicted using the linear regression equation. The linear regression equation uses the sum of squared errors to represent the loss function; The weight parameters of the statistical function are updated based on the error between the actual evaluation score and the current evaluation score.

2. The vulnerability assessment method for industrial control systems according to claim 1, characterized in that, The normal distribution function is: in, The expected score for historical evaluation. Let be the variance of the historical evaluation scores under the square root. For the purpose of evaluating scores.

3. The vulnerability assessment method for industrial control systems according to claim 1, characterized in that, Determine whether the deviation between the expected historical evaluation score and the current evaluation score exceeds a preset range; if it does, then the normal distribution function is not satisfied.

Citation Information

Patent Citations

  • Industrial control network security protection system

    CN105915402A

Cited By

  • Industrial control system security vulnerability analysis method and system for petroleum refining scene

    CN119806065B